CVE-2026-30496 Details
Description
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports both reading configuration (74 endpoints) and writing/modifying settings including volume, mute, brightness, power, network protocols enable/disable (including TELNET), display modes, and other projector functions. Any device on the same network can control the projector without authentication.
A vulnerability exists in the Optoma CinemaX P2 projector running firmware TVOS-04.24.010.04.01 and Android 8.0.0. The projector exposes an HTTP API on TCP port 2345, allowing full unauthenticated remote control of the device. This API enables users to read configuration settings through 74 endpoints and modify various projector functions, including volume, mute, brightness, power, network protocol settings (such as TELNET), display modes, and more. Any device on the same network can access and control the projector without authentication.
As of now, there is no firmware update available that addresses this vulnerability. Projector owners are advised to disconnect the device from the network if it is not needed online, isolate it on a separate VLAN or guest network, and avoid using it on shared networks. Optoma has released a firmware update for a different vulnerability that is not yet available on the Optoma USA download page, but can be manually applied for the CinemaX P2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://whitelabel.org/security/2026-02-01-smart-projector/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | New CVE Received | [email protected] |