CVE-2026-24348

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.
References
Link Resource
https://hub.ntc.swiss/ntcf-2025-145332 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nimbletech:ezcast_pro_dongle_ii_firmware:1.17478.146:*:*:*:*:*:*:*
cpe:2.3:h:nimbletech:ezcast_pro_dongle_ii:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-27 10:15

Updated : 2026-02-05 17:24


NVD link : CVE-2026-24348

Mitre link : CVE-2026-24348

CVE.ORG link : CVE-2026-24348


JSON object : View

Products Affected

nimbletech

  • ezcast_pro_dongle_ii
  • ezcast_pro_dongle_ii_firmware
CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')