CVE-2026-82989

Viewsonic vCast

Published 6 Oct 2026 · updated 6 Oct 2026 · Deferred

9.8 Critical · CVSS 3.1, CISA ADP

Description

There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints

References