Skip to main content

CISA issues update on unauthenticated ViewSonic vCast flaws

51st article in the last 90 days, one of 612 articles referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: CISA issues alert on Kotaemon improper authorization checks (Sep 2026).

Companies mentioned

Best suited for

Seniority
Analyst
Job function
Cybersecurity / Security Operations
Persona
Security Operations Leader
Buyer role
Decision Maker / Budget Holder
Buyer journey
Post Buy
Adoption curve
Late Majority
Technology maturity
Established Technology
Industry
Information Technology / Cybersecurity / Endpoint, Email & Data Security / Endpoint Security (EPP/EDR/XDR)

Our classification, not the publisher's statement. Best suited for, not only for.

ViewSonic ViewBoard smartboard devices that include ViewSonic vCast contain multiple unauthenticated vulnerabilities that can be chained to achieve full device compromise, including unauthorized access to displayed content and remote code execution without user interaction.

Three vulnerabilities in the vCast suite are identified by CVE-2026-82989, CVE-2026-82988, and CVE-2026-82987. For CVE-2026-82989, the vCast media streaming service allows a remote attacker to exfiltrate JPEG images of screen content via GET requests to an unauthenticated /snapshot or /screen API endpoint. For CVE-2026-82988, the vCast Android Package Kit (APK) delivery mechanism allows a remote attacker to trigger unprivileged file installation by providing a malicious APK URL through an unauthenticated download endpoint. For CVE-2026-82987, the vCast network services allow a remote attacker to inject arbitrary input into service endpoints via HTTP requests to exposed unauthenticated endpoints.

An unauthenticated attacker can chain these vulnerabilities via a shared network to deliver and execute arbitrary code on a vCast-based device without user interaction. Potential device-level impact includes unauthorized access to displayed content, persistent installation and execution of arbitrary applications, and full compromise of the device. Additionally, an exploited device’s connected network may be prone to lateral movement.

ViewSonic could not be reached to coordinate the vulnerability. Firmware updates should be applied when available. If possible, vCast devices should be segmented onto an isolated, secure network with strict controls, separate from systems containing sensitive data, and network activity should be monitored for suspicious vCast connections.

The guidance also notes that vCast is ViewSonic’s proprietary software suite for wireless connection between Android-based smartboards and devices running a client application, and that three distinct vulnerabilities have been identified within the vCast suite, each invoking unauthenticated endpoints.

Blog post, originally published by Alexander Lewis at kb.cert.org.

Structured data (JSON-LD)

The schema.org markup this page publishes for search engines and AI agents, exactly as they read it.

[
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#website",
    "@type": "WebSite",
    "name": "Decision Insights",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://decisioninsights.ai/search/?q={search_term_string}&submit=1"
      }
    },
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    },
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#organization",
    "@type": "Organization",
    "contactPoint": {
      "@type": "ContactPoint",
      "contactType": "customer support",
      "email": "[email protected]"
    },
    "description": "Decision Insights is a Registry of technology companies, open source projects, and industry terms, built for people and for AI agents that need sourced, structured information.",
    "logo": {
      "@type": "ImageObject",
      "url": "https://wiretap-cdn-assets.nyc3.cdn.digitaloceanspaces.com/decision-insights/[email protected]"
    },
    "name": "Decision Insights",
    "parentOrganization": {
      "@type": "Organization",
      "name": "Wiretap Labs",
      "sameAs": [
        "https://www.linkedin.com/company/wiretap-labs",
        "https://www.crunchbase.com/organization/wiretap-labs"
      ],
      "url": "https://wiretaplabs.com"
    },
    "publishingPrinciples": "https://decisioninsights.ai/standards/",
    "sameAs": [
      "https://www.linkedin.com/company/decisioninsights"
    ],
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "itemListElement": [
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai",
        "name": "Decision Insights",
        "position": 1
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/records/",
        "name": "Records",
        "position": 2
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/cisa-issues-update-on-unauthenticated-viewsonic-vcast-flaws/",
        "name": "CISA issues update on unauthenticated ViewSonic vCast flaws",
        "position": 3
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/cisa-issues-update-on-unauthenticated-viewsonic-vcast-flaws/#blogposting",
    "@type": "BlogPosting",
    "about": {
      "@type": "Organization",
      "name": "ViewSonic"
    },
    "audience": [
      {
        "@type": "Audience",
        "additionalType": "Seniority",
        "audienceType": "Analyst"
      },
      {
        "@type": "Audience",
        "additionalType": "Job function",
        "audienceType": "Cybersecurity / Security Operations"
      },
      {
        "@type": "Audience",
        "additionalType": "Persona",
        "audienceType": "Security Operations Leader"
      },
      {
        "@type": "Audience",
        "additionalType": "Buyer role",
        "audienceType": "Decision Maker / Budget Holder"
      },
      {
        "@type": "Audience",
        "additionalType": "Adoption curve",
        "audienceType": "Late Majority"
      },
      {
        "@type": "Audience",
        "additionalType": "Technology maturity",
        "audienceType": "Established Technology"
      },
      {
        "@type": "Audience",
        "additionalType": "Industry",
        "audienceType": "Information Technology / Cybersecurity / Endpoint, Email & Data Security / Endpoint Security (EPP/EDR/XDR)"
      }
    ],
    "author": {
      "@id": "https://decisioninsights.ai/author/decision-insights-threat-desk/#person",
      "@type": "Person",
      "name": "Decision Insights Threat Desk",
      "url": "https://decisioninsights.ai/author/decision-insights-threat-desk/"
    },
    "dateModified": "2026-09-24T13:44:22-06:00",
    "datePublished": "2026-09-24T13:44:18-06:00",
    "description": "ViewSonic vCast vulnerabilities CVE-2026-82989, CVE-2026-82988, and CVE-2026-82987 enable unauthenticated chaining for full device compromise.",
    "headline": "CISA issues update on unauthenticated ViewSonic vCast flaws",
    "isBasedOn": {
      "@type": "CreativeWork",
      "author": {
        "@type": "Person",
        "name": "Alexander Lewis"
      },
      "sourceOrganization": {
        "@id": "https://decisioninsights.ai/registry/department-of-homeland-security/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/department-of-homeland-security/",
        "name": "Department of Homeland Security"
      },
      "url": "https://kb.cert.org/vuls/id/234131"
    },
    "keywords": [
      "Vulnerabilities"
    ],
    "mainEntityOfPage": {
      "@id": "https://decisioninsights.ai/cisa-issues-update-on-unauthenticated-viewsonic-vcast-flaws/",
      "@type": "WebPage",
      "sdDatePublished": "2026-09-24",
      "sdPublisher": {
        "@id": "https://decisioninsights.ai/#organization"
      }
    },
    "mentions": [
      {
        "@id": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/",
        "name": "Cybersecurity and Infrastructure Security Agency (CISA)"
      }
    ],
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    }
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/author/decision-insights-threat-desk/#person",
    "@type": "Person",
    "description": "CISA advisories, vendor security bulletins, and CVE disclosures, summarized into sourced briefs. Produced under our Standards & Methodology.",
    "name": "Decision Insights Threat Desk",
    "sameAs": [
      "https://www.linkedin.com/showcase/decisioninsights/"
    ],
    "url": "https://decisioninsights.ai/author/decision-insights-threat-desk/"
  }
]

Is this your company? Get structured data for your own pages