CERT /CC has published an advisory describing three vulnerabilities in ViewSonic’s vCast software for ViewBoard smartboards: CVE-2026-82989, CVE-2026-82987 and CVE-2026-82988. The flaws affect unpatched vCast installations whose unauthenticated API endpoints are accessible to users on the local network. The article says attackers could retrieve JPEG snapshots of active screens, inject arbitrary input through HTTP endpoints and trigger installation of APKs from a supplied URL.
Chained together, the weaknesses could allow an unauthenticated attacker to execute code and take control of an Android-based smartboard without user interaction.
The report says the affected devices are used in schools and enterprises, where compromised displays could expose confidential meetings or provide a foothold for movement across an internal network. It distinguishes this potential impact from confirmed activity: security teams have found no active exploitation in the wild, although researcher Adam Mohammed Zenker has published a technical proof of concept. CERT/CC reportedly warned that the chain can deliver and execute arbitrary code over a shared network.
No official vendor patches were available when the article was published, and CERT/CC said ViewSonic could not be reached for coordinated disclosure. Administrators are advised to isolate ViewBoards on a secure network segment, prevent guest networks from communicating directly with the displays and monitor local traffic for unauthorised HTTP requests to vCast ports.