CERT/CC has revealed a chain of three vulnerabilities in ViewSonic’s vCast software that could allow unauthenticated attackers to view screens, install malicious apps, and control affected ViewBoard smart displays, raising concerns over network security in educational and corporate settings.
CERT/CC has disclosed a three-step vulnerability chain in ViewSonic’s vCast software that could let an unauthenticated attacker on the same network view screen contents, plant a malicious Android application and take over affected ViewBoard smart displays. The advisory, published on 24 September and updated the following day, concerns vCast, the wireless casting and collaboration software bundled with Android-based ViewBoard devices used in classrooms, meeting rooms and corporate environments.
The first flaw, tracked as CVE-2026-82989, affects exposed /snapshot and /screen endpoints that can be queried with unauthenticated GET requests. According to CERT/CC and independent vulnerability listings, that allows an attacker to retrieve JPEG images of whatever is being displayed, including presentations, meeting material, credentials or internal documents. A second issue, CVE-2026-82988, weakens the APK delivery mechanism by allowing an attacker to point the device at a malicious application package. A third flaw, CVE-2026-82987, permits arbitrary input to be injected into exposed HTTP services, giving an attacker a way to manipulate the software’s behaviour.
CERT/CC said the three weaknesses can be chained by someone with network access to deliver and run arbitrary code without any user interaction. Security analyses from other outlets describe the same attack path as a route to persistent device compromise, with the potential to install unauthorised Android applications and retain access to whatever is shown on the board. In practical terms, that turns a presentation display into a possible entry point for data theft and remote control.
The wider concern is not limited to the display itself. CERT/CC warned that a compromised ViewBoard could become a foothold for lateral movement to other systems on the same network. That risk is particularly relevant in schools and enterprises, where smart displays are often connected to the same internal infrastructure as staff laptops, identity services and sensitive file repositories. SC Media similarly reported that no vendor fix was available at the time of disclosure, leaving segmentation and monitoring as the main temporary controls.
ViewSonic’s status for all three CVEs was listed as unknown in the CERT/CC note, and the centre said it had been unable to reach the vendor during coordinated disclosure. Until firmware updates or formal guidance arrive, organisations are being urged to isolate ViewBoard and vCast devices on separate VLANs, restrict management and casting traffic with firewall rules, watch for suspicious requests to /snapshot, /screen or APK download paths, and review deployed Android applications for anything unfamiliar.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





