10.12.2025 - The Swiss National Cyber Security Centre (NCSC) was involved in a Coordinated Vulnerability Disclosure reported by the Swiss National Test Institute for Cybersecurity (NTC) regarding multiple vulnerabilities affecting EZCast Pro II Dongle from NimbleTech, allowing to bypass authentication and authorization checks.
Until a firmware patch is made available by the vendor, users are advised to disconnect the dongle from their local network and limit its use strictly to Access Point functionality to minimize the attack surface and change the default password.
NimbleTech acknowledged the vulnerabilitie, they were not able to produce a fix within the deadline exceeding 90 days given by the NCSC.
CVEs in this advisory
CVE-2025-13954 - Hard-coded cryptographic keys in EZCast Pro II Dongle
Hard-coded cryptographic keys in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI
CVE-2025-13955 - Predictable Default Wi-Fi Password in EZCast Pro II Dongle
Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II version 1.17478.146 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default password from observable device identifiers.
Affected versions
Both vulnerabilities were reported against EZCast Pro II Dongle version 1.17478.146, as we are not aware of a firmware patch addressing those vulnerabilities at the time of this advisory all other versions should be considered vulnerable.
Update 28.05.2026
NimbleTech confirmed to the NCSC that CVE-2025-13954 and CVE-2025-13955 were fixed in Version 1.17478.177 as acknowleged in their release notes.
Release note : https://www.nimbletech.com.tw/index.php/release-note/
Last modification 28.05.2026