Nimbletech's vulnerability footprint centers on its EZCast Pro Dongle II wireless presentation and casting device and associated firmware, with the recurring exposure rooted in application-layer input-handling and credential-management weaknesses including improper input validation, cross-site request forgery, cross-site scripting, and hard-coded credentials. Treat this as a compact vendor profile specific to embedded presentation hardware; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nimbletech over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24345HIGH Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI | Jan 27, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-24346CRITICAL Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application | Jan 27, 2026 | 9.1 | 26 | NO | NO |
CVE-2026-24348MEDIUM Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI | Jan 27, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-24347MEDIUM Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory | Jan 27, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nimbletech.
Media articles that mention a CVE ID that affects a product developed by Nimbletech — matched by CVE ID, not by vendor name.