Junglewise Threat Intelligence

CVE-2026-30282: UXGROUP LLC Cast to TV Screen Mirroring path traversal in file import

CVE-2026-30282 · Severity: critical · CVSS 9 · Published 2026-03-31

Executive brief

UXGROUP LLC's Cast to TV - Screen Mirroring app, a popular tool for streaming mobile content to televisions, contains a critical security flaw in its file import process. An attacker can exploit this to access or overwrite private application data, potentially leading to the theft of user account information or the execution of unauthorized commands. This could result in unauthorized access to personal media and sensitive user accounts.

Technical details

A path traversal vulnerability (CWE-22) exists in the file import process of the Cast to TV - Screen Mirroring Android application (ai.chatbot.alpha.chatapp). Due to insufficient validation of file paths during import, a malicious application on the same device can use crafted paths to access the app's private internal storage. This allows an attacker to read sensitive data (such as session tokens) or overwrite critical internal files. The vulnerability can be triggered when a user interacts with a malicious app, which then automates the data extraction to shared external storage for exfiltration. CISA-ADP has assigned a CVSS score of 9.0, noting that it can lead to total technical impact.

Affected products

  • UXGROUP LLC Cast to TV - Screen Mirroring 2.2.77

Timeline

  • 2026-03-31: disclosed: Vulnerability disclosed by Secsys-FDU and assigned CVE-2026-30282
  • 2026-03-31: advisory: NVD published the CVE record

References