Vulnerability Description
Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nimbletech | Ezcast Pro Dongle Ii Firmware | 1.17478.146 |
| Nimbletech | Ezcast Pro Dongle Ii | - |
Related Weaknesses (CWE)
References
- https://hub.ntc.swiss/ntcf-2025-32832Third Party Advisory
FAQ
What is CVE-2026-24345?
CVE-2026-24345 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI
How severe is CVE-2026-24345?
CVE-2026-24345 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24345?
Check the references section above for vendor advisories and patch information. Affected products include: Nimbletech Ezcast Pro Dongle Ii Firmware, Nimbletech Ezcast Pro Dongle Ii.