CVE-2026-30282 is an arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77, enabling attackers to overwrite critical internal files via the file import process. Rated Critical with a CVSS score of 9.0, this vulnerability has a network attack vector, low attack complexity, and requires low privileges and user interaction. Successful exploitation could lead to arbitrary code execution or significant information exposure. There is currently no evidence of active exploitation, nor is public exploit code available in common repositories like Metasploit or ExploitDB. While not on the CISA KEV catalog, it has garnered minor community discussion since its recent publication.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.77CPE matchmatch criteria | cpe:2.3:a:uxgroupllc:cast_to_tv:2.2.77:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.