CVE-2026-82988 PUBLISHED

CVE-2026-82988

Assigner: certcc
Reserved: 31.08.2026 Published: 05.10.2026 Updated: 06.10.2026

There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint

Product Status

Vendor Viewsonic
Product vCast
Versions
  • affected from v0.0.0 to v3.2.715 (incl.)

References

Problem Types

  • CWE-287 Improper Authentication
  • CWE-434 Unrestricted Upload of File with Dangerous Type
  • CWE-502 Deserialization of Untrusted Data