Home

Description

Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

PUBLISHED Reserved 2026-01-22 | Published 2026-01-27 | Updated 2026-01-27 | Assigner NCSC.ch




MEDIUM: 6.8CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/RE:L

Problem types

CWE-20 Improper Input Validation

Product status

Default status
affected

1.17478.146
affected

Credits

Swiss National Test Institute for Cybersecurity NTC finder

Redguard AG finder

Swiss National Cybersecurity Centre coordinator

References

hub.ntc.swiss/ntcf-2025-32832

cve.org (CVE-2026-24345)

nvd.nist.gov (CVE-2026-24345)

Download JSON