CVE-2026-24348

M

ultiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.

References
Link Resource
https://hub.ntc.swiss/ntcf-2025-145332 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nimbletech:ezcast_pro_dongle_ii_firmware:1.17478.146:*:*:*:*:*:*:*
cpe:2.3:h:nimbletech:ezcast_pro_dongle_ii:-:*:*:*:*:*:*:*

History

05 Feb 2026, 17:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:o:nimbletech:ezcast_pro_dongle_ii_firmware:1.17478.146:*:*:*:*:*:*:*
cpe:2.3:h:nimbletech:ezcast_pro_dongle_ii:-:*:*:*:*:*:*:*
References () https://hub.ntc.swiss/ntcf-2025-145332 - () https://hub.ntc.swiss/ntcf-2025-145332 - Third Party Advisory
CWE CWE-79
First Time Nimbletech ezcast Pro Dongle Ii Firmware
Nimbletech ezcast Pro Dongle Ii
Nimbletech

27 Jan 2026, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 10:15

Updated : 2026-02-05 17:24


NVD link : CVE-2026-24348

Mitre link : CVE-2026-24348

CVE.ORG link : CVE-2026-24348


JSON object : View

CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')