CVE-2026-82989
Summary
| CVE | CVE-2026-82989 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 00:16:37 UTC |
| Updated | 2026-10-06 00:16:37 UTC |
| Description | There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints |
Risk And Classification
Problem Types: CWE-147 Improper Neutralization of Input During Web Page Generation (“Input Injection”) | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| blog.l3afs.space/posts/Vcast-Viewsonic-RCE-chain | [email protected] | blog.l3afs.space | |
| kb.cert.org/vuls/id/234131 | [email protected] | kb.cert.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.