CVE-2019-3929
KEV PoC ×2largeUnauthenticated root command injection in multi-vendor wireless presentation gateways
CISA: Crestron Multiple Products Command Injection Vulnerability
CVE-2019-3929 is an unauthenticated OS command injection in the file_transfer.cgi HTTP endpoint of the embedded web server used by a family of wireless presentation gateways. A remote attacker who can reach the device's web interface sends a crafted request to file_transfer.cgi, causing arbitrary operating system commands to run as root. Successful exploitation yields full compromise of the device, which typically sits inside the corporate network and can be used as a pivot into internal systems. Affected products span Crestron (AM-100, AM-101), Barco wePresent (WiPG-1000P, WiPG-1600W), Extron ShareLink 200/250, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, and InFocus LiteShow3/LiteShow4 — most of which are OEM variants of the same platform. The flaw has a public proof of concept (Exploit-DB 46786, Tenable TRA-2019-20), a 99% EPSS score, and is listed in CISA's Known Exploited Vulnerabilities catalog as of 2022-04-15, indicating exploitation in the wild.
What to do: Apply vendor firmware updates per CISA's required action — for Barco wePresent WiPG-1600W this means 2.4.1.19 or later, and owners of the other listed models should obtain the fixed firmware from each vendor's advisory (Tenable TRA-2019-20 / Exploit-DB 46786). Until patched, restrict the devices' web interface (including the file_transfer.cgi endpoint) from internet exposure and limit access to trusted management or presentation VLANs. Check device logs and network traffic for unexpected requests to file_transfer.cgi, and treat any internet-facing unit as potentially compromised since the flaw allows unauthenticated root-level access.
| Crestron AM-100 | firmware 1.6.0.2 |
| Crestron AM-101 | firmware 2.7.0.1 |
| Barco wePresent WiPG-1000P | firmware 2.3.0.10 |
| Barco wePresent WiPG-1600W | firmware before 2.4.1.19 |
| Extron ShareLink 200 | firmware 2.0.3.4 |
| Extron ShareLink 250 | firmware 2.0.3.4 |
| Teq AV IT WIPS710 | firmware 1.1.0.7 |
| SHARP PN-L703WA | firmware 1.4.2.3 |
| Optoma WPS-Pro | firmware 1.0.0.5 |
| Blackbox HD Wireless Presentation System | firmware 1.0.0.5 |
| InFocus LiteShow3 | firmware 1.0.16 |
| InFocus LiteShow4 | firmware 2.0.0.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
- Affected
- Crestron Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- crestronbarcoextronteqavitsharpoptomablackboxinfocus
- Products
- am-100 firmware, am-101 firmware, wepresent wipg-1000p firmware, wepresent wipg-1600w firmware, sharelink 200 firmware, sharelink 250 firmware, wips710 firmware, pn-l703wa firmware, wps-pro firmware, hd wireless presentation system firmware, liteshow3 firmware, liteshow4 firmware
- Weakness
- CWE-79, CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.