CVE-2026-30496Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports both reading configuration (74 endpoints) and writing/modifying settings including volume, mute, brightness, power, network protocols enable/disable (including TELNET), display modes, and other projector functions. Any device on the same network can control the projector without authentication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-11: 3Mentions · 2026-05-31: 1Technical Details · 2026-05-11: 205-1105-31
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-113
Disclosure2General1
2026-05-311
General1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.8 CRITICAL · CVE-2026-30496 · 9.8 → 04.24.010.04 CVE: CVE-2026-30496 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-30496, a critical 9.8 CVSS vulnerability, without providing exploitation details or patch information.

    1000030
    197 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-30496 Optoma CinemaX P2の脆弱性について https://www.cybernote.click/2026/05/21/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-30496-optoma-cinemax-p2%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The text references a vulnerability (CVE‑2026‑30496) in Optoma CinemaX P2 and provides a link to an article, but contains no specific technical details, exploits, or mitigation information.

    0000047
    209 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-30496-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text merely references a CVE via a URL and some hashtags without providing any substantive details about the vulnerability, exploitation, or remediation.

    0000020
    188 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-30496 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full…

    Post summary

    The text announces a critical vulnerability (CVE-2026-30496) in Optoma CinemaX P2 projectors, providing technical details such as CVSS rating and affected API, but does not mention exploitation, PoC, patch, or mitigation.

    0000038
    197 followersView on X

Explore more