CVE-2026-24348

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.
References
Link Resource
https://hub.ntc.swiss/ntcf-2025-145332 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nimbletech:ezcast_pro_dongle_ii_firmware:1.17478.146:*:*:*:*:*:*:*
cpe:2.3:h:nimbletech:ezcast_pro_dongle_ii:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) Múltiples vulnerabilidades de cross-site scripting en la Admin UI de EZCast Pro II versión 1.17478.146 permiten a los atacantes ejecutar código JavaScript arbitrario en el navegador de otros usuarios de la Admin UI.

05 Feb 2026, 17:24

Type Values Removed Values Added
First Time Nimbletech ezcast Pro Dongle Ii
Nimbletech
Nimbletech ezcast Pro Dongle Ii Firmware
CWE CWE-79
CPE cpe:2.3:o:nimbletech:ezcast_pro_dongle_ii_firmware:1.17478.146:*:*:*:*:*:*:*
cpe:2.3:h:nimbletech:ezcast_pro_dongle_ii:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://hub.ntc.swiss/ntcf-2025-145332 - () https://hub.ntc.swiss/ntcf-2025-145332 - Third Party Advisory

27 Jan 2026, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 10:15

Updated : 2026-06-17 10:22


NVD link : CVE-2026-24348

Mitre link : CVE-2026-24348

CVE.ORG link : CVE-2026-24348


JSON object : View

Products Affected

nimbletech

  • ezcast_pro_dongle_ii_firmware
  • ezcast_pro_dongle_ii
CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')