OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-82988

HIGH · CVSS 7.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vCast APK delivery mechanism in ViewSonic ViewBoard is vulnerable to arbitrary file download, allowing remote, unauthenticated attackers to initiate unprivileged APK installations by exploiting an unauthenticated download endpoint. This vulnerability could lead to the installation of malicious applications, potentially compromising the device's integrity and security. Organizations using ViewSonic ViewBoard should prioritize addressing this issue to mitigate risks associated with unauthorized APK installations.

CVE
CVE-2026-82988
Severity
HIGH
CVSS
7.5
EPSS
0.27%

Original NVD Description

There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint