CVE-2026-82988

Viewsonic vCast

Published 6 Oct 2026 · updated 6 Oct 2026 · Deferred

7.5 High · CVSS 3.1, CISA ADP

Description

There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint

References