Executive brief
The EZCast Pro II, a wireless display dongle used for presentations and screen sharing, contains hard-coded security keys in its administrative interface. An attacker on the same network can use these keys to bypass security checks and gain full control over the device's settings. This could lead to unauthorized access to presentation data, service disruption, or the use of the device as a foothold for further network attacks.
Technical details
The EZCast Pro II Dongle (and Box II) contains hard-coded cryptographic keys within its Web Admin interface. This vulnerability (CWE-798) allows an unauthenticated attacker with network access to the device to bypass authorization mechanisms. By leveraging these static keys, an attacker can gain full administrative privileges over the device UI. The vulnerability was identified in version 1.17478.146 and is addressed in firmware version 1.17478.177, which also introduces mandatory password changes.
Affected products
- NimbleTech EZCast Pro II Dongle before 1.17478.177
Timeline
- 2025-12-10: disclosed: Advisory published by Swiss NCSC
- 2025-12-10: advisory: NVD entry created
- 2025-12-10: patched: Firmware version 1.17478.177 released to address the issue