Critical ViewSonic vCast Vulnerabilities Allow Attackers to Gain Full Control Over the Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Critical vulnerabilities in ViewSonic’s vCast software could allow attackers on the same network to steal screen content, install malicious Android applications, and potentially gain full control of affected ViewBoard smart displays.

The issues were disclosed in CERT Coordination Center Vulnerability Note VU#234131, published on September 24, 2026. The advisory states that multiple unauthenticated network endpoints in the vCast suite can be chained together to compromise a device without requiring user interaction.

ViewSonic ViewBoards are Android-based interactive smart displays widely used in schools, offices, meeting rooms, and other enterprise environments. The devices use the vCast software suite to support wireless screen sharing and connections between the smartboard and client devices.

Researchers identified three vulnerabilities affecting exposed vCast services. The flaws are tracked as CVE-2026-82987, CVE-2026-82988, and CVE-2026-82989.

ViewSonic vCast Vulnerabilities

CVE-2026-82989 affects vCast’s media streaming service. An attacker can send unauthenticated GET requests to the /snapshot or /screen API endpoints to retrieve JPEG images of the device display.

This could expose sensitive presentations, meeting discussions, credentials, documents, educational material, or other information displayed on an affected ViewBoard.

CVE-2026-82988 impacts the APK delivery mechanism used by vCast. The flaw allows a remote attacker to supply a malicious APK URL to an unauthenticated download endpoint. The device can then download and install the supplied Android application without authentication.

The third issue, CVE-2026-82987, allows attackers to inject arbitrary input into exposed vCast service endpoints through HTTP requests. While each flaw creates serious exposure on its own, the main risk comes from chaining the vulnerabilities together.

An attacker connected to the same shared network could first access screen snapshots to identify valuable content or active users. They could then abuse the exposed APK installation capability to place a malicious application on the device. This could provide persistent access, enable monitoring, execute arbitrary code, and give the attacker control over the smartboard.

CERT/CC warned that a compromised ViewBoard may also become a foothold for lateral movement within the connected network. This creates added risk for organizations that deploy smart displays on the same network as employee workstations, servers, administrative systems, or sensitive data repositories.

At the time of the advisory, ViewSonic’s vendor status was listed as unknown, and CERT/CC said it could not reach the company during vulnerability coordination. Organizations should apply firmware updates as soon as ViewSonic releases security fixes.

Until patches are released, administrators should isolate vCast-enabled ViewBoards on a dedicated network segment, restrict access to required users and devices, and prevent unnecessary communication with internal systems. Security teams should also monitor network traffic for suspicious HTTP requests and unexpected connections involving vCast services.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical ViewSonic vCast Vulnerabilities Allow Attackers to Gain Full Control Over the Device appeared first on Cyber Security News.