Vulnerability Management

3 zero-day flaws in ViewSonic’s vCast software allow remote screen viewing, app installation

As reported by Cyber Insider, three zero-day vulnerabilities have been discovered in ViewSonic's vCast software, potentially allowing attackers on the same network to gain significant control over affected devices. These flaws, which were disclosed by CERT/CC on September 24, could enable unauthorized access to smartboard screens and the installation of malicious applications.

The vulnerabilities affect ViewSonic ViewBoards, interactive displays commonly used in educational and enterprise settings. An attacker on the local network can exploit CVE-2026-82989 to view smartboard screens by accessing exposed API endpoints. Furthermore, CVE-2026-82988 allows attackers to trick the device into downloading and installing arbitrary Android applications by providing a malicious URL. The third vulnerability, CVE-2026-82987, enables unauthenticated users to send input commands to the device. These flaws can be chained together, allowing an attacker to remotely install malicious applications and potentially take complete control of the ViewBoard.

Successful exploitation could lead to persistent malicious apps, unauthorized data access, arbitrary code execution, and provide a pivot point for lateral movement within a network. CERT/CC warns that ViewSonic has not yet provided a fix, and recommends isolating these devices on restricted network segments and monitoring for suspicious activity.

Source: Cyber Insider

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds