UXGROUP Cast to TV Screen Mirroring Arbitrary File Overwrite Vulnerability Allowing Code Execution or Information Exposure

Vulnerability

A vulnerability allowing arbitrary file overwriting has been identified in UXGROUP LLC's Cast to TV Screen Mirroring application, version 2.2.77. This vulnerability arises from inadequate security validation during the file import process, enabling attackers to overwrite critical internal files. Exploitation of this vulnerability could lead to arbitrary code execution or unauthorized information disclosure.

Impact

Exploitation of this vulnerability allows for arbitrary file overwriting, which could be used to execute malicious code or access sensitive information.

Reproduction

The vulnerability can be reproduced by importing a file through the application's file import process. A crafted file path can be used to overwrite internal files, taking advantage of directory traversal techniques to access sensitive data stored within the app's private storage. Once the data is extracted, it can be written to shared external storage, where it can be accessed by other applications on the device.

Added: Mar 31, 2026, 7:04 PM
Updated: Mar 31, 2026, 7:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
5.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.