Vulnerability Description
Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nimbletech | Ezcast Pro Dongle Ii Firmware | 1.17478.146 |
| Nimbletech | Ezcast Pro Dongle Ii | - |
Related Weaknesses (CWE)
References
- https://hub.ntc.swiss/ntcf-2025-13993Third Party Advisory
FAQ
What is CVE-2026-24346?
CVE-2026-24346 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application
How severe is CVE-2026-24346?
CVE-2026-24346 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-24346?
Check the references section above for vendor advisories and patch information. Affected products include: Nimbletech Ezcast Pro Dongle Ii Firmware, Nimbletech Ezcast Pro Dongle Ii.