# ViewSonic vCast flaws enable smartboard takeover

Published: 2026-09-24 · Severity: routine · Sectors: education, technology
Canonical: https://vorant.io/reports/54845b88-6f03-5991-9495-3b474fa8a311/viewsonic-vcast-flaws-enable-smartboard-takeover

> Three chainable unauthenticated vulnerabilities in ViewSonic vCast let remote attackers fully compromise ViewBoard smartboards without user interaction.

CERT/CC has published an advisory (VU#234131) detailing three unauthenticated vulnerabilities in ViewSonic's vCast software, which ships on Android-based ViewBoard smartboard devices widely deployed in enterprise and educational settings. The flaws affect vCast's wireless-connection network services: CVE-2026-82989 allows remote exfiltration of screen content via an unauthenticated snapshot/screen API; CVE-2026-82988 allows unprivileged installation of an arbitrary APK via an unauthenticated download endpoint; and CVE-2026-82987 allows arbitrary input injection into exposed, unauthenticated service endpoints.

Chained together, these issues let an unauthenticated attacker on the same network deliver and execute arbitrary code on a vCast-enabled device with no user interaction, resulting in full device compromise, persistent malicious app installation, unauthorized viewing of displayed content, and a potential pivot point for lateral movement into the connected network. ViewSonic could not be reached during the coordination process, so no vendor patch is currently available.

Defenders should watch for unusual HTTP traffic to vCast network endpoints, apply firmware updates as soon as ViewSonic releases them, and in the meantime isolate ViewBoard/vCast devices on segmented networks separate from systems holding sensitive data. Given the lack of authentication requirements, the no-user-interaction chain, and no vendor fix, this warrants prompt mitigation in affected environments, particularly schools and enterprises using ViewBoard smartboards.

## Mentioned in this report

- Vulnerabilities: CVE-2026-82987, CVE-2026-82988, CVE-2026-82989

Source reporting: https://kb.cert.org/vuls/id/234131

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/54845b88-6f03-5991-9495-3b474fa8a311/viewsonic-vcast-flaws-enable-smartboard-takeover.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
