Executive brief
EShare is a wireless screen-sharing and collaboration application used to cast content from personal devices to smart TVs. A security flaw allows an attacker on the same local network to bypass security protections and guess the screen-sharing access code. If successful, an unauthorized user could take control of the display to show harmful or inappropriate content, disrupting meetings or public displays.
Technical details
A rate-limiting bypass vulnerability exists in ESharePro versions through 7.6.0707. The application fails to properly restrict the frequency of connection attempts, allowing an attacker with local network access to perform a brute-force attack against the screen-sharing PIN or access code. Successful exploitation enables the attacker to establish an unauthorized session and cast arbitrary content to the screen. The vendor has released a security update to address this issue, and users are advised to update to the latest version.
Affected products
- EShare ESharePro through 7.6.0707
Timeline
- 2026-07-28: advisory: CSA Singapore and NVD published the advisory.
- 2026-07-28: patched: Vendor released security updates.