Vulnerability in EShare Application
28 July 2026
A vulnerability has been discovered in EShare’s application. Special thanks to the informer and EShare for their involvement as part of CSA's Responsible Vulnerability Disclosure Policy.
Background
CSA has issued a CVE ID (CVE-2026-55977) for the vulnerability reported in EShare’s application which allows wireless screen mirroring, casting and collaboration. Attackers may exploit the vulnerability to interrupt normal usage of the application and display harmful content on affected screens. The product owner, EShare, has released a security update to address it.
Impact
Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code and potentially displaying harmful content on the affected screen. The vulnerability has a Common Vulnerability Scoring System (CVSS 3.1) score of 3.3 out of 10.
Affected Products
The vulnerability affects EShare Smart-TV Screensharing App versions through 7.6.0707.
Mitigation
Users and administrators of affected product versions are advised to update to the latest version immediately. Please refer to the update here to download the update file. After downloading, click the file and follow the step-by-step installation process.
To check if a smart TV is running an affected version of the EShare application, locate the EShare application via the installed applications list on the smart TV's home screen or settings menu, and view the version details under the application information or settings. The steps to access information on the application may vary depending on the smart TV brand and model.
Special Thanks to:
Informer: Mr James O'Connor
Product Owner: EShare
