CVE-2026-82989

Summary

There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints

Affected Software

VendorProductVersion RangeStatus
ViewsonicvCastv0.0.0 <= v3.2.715affected

Weaknesses

  • CWE-147 Improper Neutralization of Input During Web Page Generation (“Input Injection”)
  • CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

References