CVE-2026-24348: Nimbletech Ezcast Pro Dongle Ii Firmware

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.

Affected products

  • Nimbletech Ezcast Pro Dongle Ii Firmware: version 1.17478.146 only

Published 2026-01-27. Last modified 2026-06-17.