CVE-2026-24348

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.
References
Link Resource
https://hub.ntc.swiss/ntcf-2025-145332 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nimbletech:ezcast_pro_dongle_ii_firmware:1.17478.146:*:*:*:*:*:*:*
cpe:2.3:h:nimbletech:ezcast_pro_dongle_ii:-:*:*:*:*:*:*:*

History

05 Feb 2026, 17:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://hub.ntc.swiss/ntcf-2025-145332 - () https://hub.ntc.swiss/ntcf-2025-145332 - Third Party Advisory
First Time Nimbletech ezcast Pro Dongle Ii
Nimbletech
Nimbletech ezcast Pro Dongle Ii Firmware
CWE CWE-79
CPE cpe:2.3:o:nimbletech:ezcast_pro_dongle_ii_firmware:1.17478.146:*:*:*:*:*:*:*
cpe:2.3:h:nimbletech:ezcast_pro_dongle_ii:-:*:*:*:*:*:*:*

27 Jan 2026, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 10:15

Updated : 2026-02-05 17:24


NVD link : CVE-2026-24348

Mitre link : CVE-2026-24348

CVE.ORG link : CVE-2026-24348


JSON object : View

Products Affected

nimbletech

  • ezcast_pro_dongle_ii
  • ezcast_pro_dongle_ii_firmware
CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')