CVE-2026-30282

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.
References
Link Resource
http://cast.com Broken Link
https://appcraze.co/ Product
https://github.com/Secsys-FDU/AF_CVEs/issues/27 Third Party Advisory
https://secsys.fudan.edu.cn/ Not Applicable
Configurations

Configuration 1 (hide)

cpe:2.3:a:uxgroupllc:cast_to_tv:2.2.77:*:*:*:*:android:*:*

History

07 Apr 2026, 21:00

Type Values Removed Values Added
First Time Uxgroupllc
Uxgroupllc cast To Tv
References () http://cast.com - () http://cast.com - Broken Link
References () https://appcraze.co/ - () https://appcraze.co/ - Product
References () https://github.com/Secsys-FDU/AF_CVEs/issues/27 - () https://github.com/Secsys-FDU/AF_CVEs/issues/27 - Third Party Advisory
References () https://secsys.fudan.edu.cn/ - () https://secsys.fudan.edu.cn/ - Not Applicable
CPE cpe:2.3:a:uxgroupllc:cast_to_tv:2.2.77:*:*:*:*:android:*:*

31 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 18:16

Updated : 2026-04-07 21:00


NVD link : CVE-2026-30282

Mitre link : CVE-2026-30282

CVE.ORG link : CVE-2026-30282


JSON object : View

Products Affected

uxgroupllc

  • cast_to_tv
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path