← Back to feed
Breaches & RansomwareEmerging1 sourceSep 24, 2026 · 19:27via CERT/CC Vulnerability Notes

VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise

Brief

Overview

ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise.

Description

ViewSonic ViewBoards are widely used smart display devices (smartboard), typically deoloyed in enterprise and educational environments. vCast is ViewSonic’s proprietary software suite for wireless connection between smartboards, which are Android-based systems, and devices running a client application. Three distinct vulnerabilities, all invoking unauthenticated endpoints, have been identified within the vCast suite.

CVE-2026-82989

vCast’s media streaming service allows a remote attacker to exfiltrate JPEG images of screen content via GET requests to an unauthenticated /snapshot or /screen API endpoint.

Read more on CERT/CC Vulnerability Notes→