VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
Unauthenticated ViewSonic vCast flaws can leak screens and fully compromise ViewBoard devices.
CERT/CC published VU#234131 on three unauthenticated flaws in ViewSonic vCast, the wireless suite shipped on Android-based ViewBoard smartboards used in enterprises and schools. CVE-2026-82989 exposes /snapshot and /screen endpoints that return JPEG images of the display. CVE-2026-82988 accepts a remote APK URL on an unauthenticated download endpoint, and CVE-2026-82987 allows arbitrary input injection into exposed service endpoints. Chained over a shared network, the issues can install and run arbitrary apps without user interaction; ViewSonic could not be reached, so CERT recommends segmentation until firmware updates are available.
68