vCast’s network services allow a remote attacker to inject arbitrary input into service endpoints via HTTP requests to exposed unauthenticated endpoints.
https://kb.cert.org/vuls/id/234131
Source: Mitre, NVD
Published: 2026-09-25