PT-2026-98306 · Undefined · Undefined

CVE-2026-82988

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Three critical unauthenticated CVEs in ViewSonic vCast (CVE-2026-82987, CVE-2026-82988, CVE-2026-82989) allow a remote attacker to chain screen exfiltration with arbitrary APK installation for full device compromise. These are Android-based ViewBoard smartboards, heavily deployed in enterprise and education.
Technical Breakdown - CVE-2026-82989 (Info Disclosure): Unauthenticated GET requests to /snapshot or /screen endpoints exfiltrate JPEG screen captures. - CVE-2026-82988 (Code Execution): Unauthenticated APK download endpoint allows attacker to trigger installation of a malicious package by providing a crafted URL. - CVE-2026-82987 (Input Injection): Unauthenticated HTTP endpoints allow arbitrary input injection into service endpoints. - Attack Chain: Shared network access → Snapshot screen data → Inject malicious APK URL → Full device compromise. - No IOCs provided in the advisory; detection relies on network monitoring for anomalous HTTP requests to these endpoints.
Defense Block external access to vCast service ports on ViewBoards. Monitor for unexpected GET requests to /snapshot or /screen and unauthorized APK download triggers. Segment smartboards from untrusted networks.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-82988

Affected Products

Undefined