---
id: CVE-2026-30282
title: >-
  An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen
  Mirroring v2.2.77 allows attackers to overwrite critical internal files via
  the file import process, leading to arbtrary code execution or information
  exposure.
summary: >-
  An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen
  Mirroring v2.2.77 allows attackers to overwrite critical internal files via
  the file import process, leading to arbtrary code execution or information
  exposure.
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-73
vendor: uxgroupllc
product: cast_to_tv
affected:
  - cast_to_tv = 2.2.77
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30282'
references:
  - url: 'https://appcraze.co/'
    label: cve@mitre.org
  - url: 'https://github.com/Secsys-FDU/AF_CVEs/issues/27'
    label: cve@mitre.org
  - url: 'https://secsys.fudan.edu.cn/'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00363
epssPercentile: 0.30205
ingestedAt: '2026-07-24T20:38:03.200Z'
---

## Overview

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

## Affected

- `cast_to_tv = 2.2.77`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
