CVE-2026-24347 MEDIUM

CVE-2026-24347: Arbitrary file write to /tmp directory in EZCast Pro II Dongle

Vendor Ezcast
Product EZCast Pro II
Weakness CWE-20 · Input validation
Published January 27, 2026
Last update January 27, 2026

CVSS base score

5.7/10
Attack vector Adjacent
Attack complexity High
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U

What the vulnerability does

01Description

Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory

Key dates

02Disclosure timeline

January 27, 2026 CVE published
January 27, 2026 Record updated