{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/234131#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise.\r\n\r\n### Description\r\nViewSonic ViewBoards are widely used smart display devices (smartboard), typically deoloyed in enterprise and educational environments. vCast is ViewSonic’s proprietary software suite for wireless connection between smartboards, which are Android-based systems, and devices running a client application. Three distinct vulnerabilities, all invoking unauthenticated endpoints, have been identified within the vCast suite.\r\n\r\n**CVE-2026-82989**\r\nvCast’s media streaming service allows a remote attacker to exfiltrate JPEG images of screen content via GET requests to an unauthenticated `/snapshot` or `/screen` API endpoint. \r\n\r\n**CVE-2026-82988**\r\nvCast’s Android Package Kit (APK) delivery mechanism allows a remote attacker to trigger unprivileged file installation by providing a malicious APK URL through an unauthenticated download endpoint. \r\n \r\n**CVE-2026-82987**\r\nvCast’s network services allow a remote attacker to inject arbitrary input into service endpoints via HTTP requests to exposed unauthenticated endpoints\r\n\r\n### Impact\r\nAn unauthenticated attacker can chain these vulnerabilities via a shared network to deliver and execute arbitrary code on a vCast-based device without user interaction. Potential device-level impact includes unauthorized access to displayed content, persistent installation and execution of arbitrary applications, and full compromise of the device. Additionally, an exploited device’s connected network may be prone to lateral movement.\r\n\r\n### Solution\r\nUnfortunately, ViewSonic could not be reached to coordinate the vulnerability. In the meantime, firmware updates should be applied when available. If possible, segment vCast devices onto an isolated, secure network with strict controls, separate from systems containing sensitive data. Network activity should be monitored for suspicious vCast connections.\r\n\r\n### Acknowledgements\r\nThank you to Adam Mohammed Zenker for this report. This document was written by Alexander Lewis.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/234131"},{"url":"https://blog.l3afs.space/posts/Vcast-Viewsonic-RCE-chain/","summary":"https://blog.l3afs.space/posts/Vcast-Viewsonic-RCE-chain/"}],"title":"ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise","tracking":{"current_release_date":"2026-09-24T19:29:39+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.49"}},"id":"VU#234131","initial_release_date":"2026-09-24 19:27:42.209305+00:00","revision_history":[{"date":"2026-09-24T19:29:39+00:00","number":"1.20260924192939.2","summary":"Released on 2026-09-24T19:29:39+00:00"}],"status":"final","version":"1.20260924192939.2"}},"vulnerabilities":[{"title":"There exists a screen capture endpoint in vCast media streaming service in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to capture and exfiltrate the current screen content via GET requests to an unauthenticated /snapshot or /screen endpoint returning JPEGs.","notes":[{"category":"summary","text":"There exists a screen capture endpoint in vCast media streaming service in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to capture and exfiltrate the current screen content via GET requests to an unauthenticated /snapshot or /screen endpoint returning JPEGs"}],"cve":"CVE-2026-82987","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#234131"}]},{"title":"There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint.","notes":[{"category":"summary","text":"There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint"}],"cve":"CVE-2026-82988","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#234131"}]},{"title":"There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints.","notes":[{"category":"summary","text":"There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints"}],"cve":"CVE-2026-82989","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#234131"}]}],"product_tree":{"branches":[]}}