CVE-2026-82988

Summary

There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint

Affected Software

VendorProductVersion RangeStatus
ViewsonicvCastv0.0.0 <= v3.2.715affected

Weaknesses

  • CWE-287 Improper Authentication
  • CWE-434 Unrestricted Upload of File with Dangerous Type
  • CWE-502 Deserialization of Untrusted Data

References