CVE-2026-82989 PUBLISHED

CVE-2026-82989

Assigner: certcc
Reserved: 31.08.2026 Published: 05.10.2026 Updated: 06.10.2026

There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints

Product Status

Vendor Viewsonic
Product vCast
Versions
  • affected from v0.0.0 to v3.2.715 (incl.)

References

Problem Types

  • CWE-147 Improper Neutralization of Input During Web Page Generation (“Input Injection”)
  • CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')