ZeroHour

CVE-2019-3929

KEV PoC ×2large

Unauthenticated root command injection in multi-vendor wireless presentation gateways

CISA: Crestron Multiple Products Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2019-3929 is an unauthenticated OS command injection in the file_transfer.cgi HTTP endpoint of the embedded web server used by a family of wireless presentation gateways. A remote attacker who can reach the device's web interface sends a crafted request to file_transfer.cgi, causing arbitrary operating system commands to run as root. Successful exploitation yields full compromise of the device, which typically sits inside the corporate network and can be used as a pivot into internal systems. Affected products span Crestron (AM-100, AM-101), Barco wePresent (WiPG-1000P, WiPG-1600W), Extron ShareLink 200/250, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, and InFocus LiteShow3/LiteShow4 — most of which are OEM variants of the same platform. The flaw has a public proof of concept (Exploit-DB 46786, Tenable TRA-2019-20), a 99% EPSS score, and is listed in CISA's Known Exploited Vulnerabilities catalog as of 2022-04-15, indicating exploitation in the wild.

What to do: Apply vendor firmware updates per CISA's required action — for Barco wePresent WiPG-1600W this means 2.4.1.19 or later, and owners of the other listed models should obtain the fixed firmware from each vendor's advisory (Tenable TRA-2019-20 / Exploit-DB 46786). Until patched, restrict the devices' web interface (including the file_transfer.cgi endpoint) from internet exposure and limit access to trusted management or presentation VLANs. Check device logs and network traffic for unexpected requests to file_transfer.cgi, and treat any internet-facing unit as potentially compromised since the flaw allows unauthenticated root-level access.

Affected
Crestron AM-100firmware 1.6.0.2
Crestron AM-101firmware 2.7.0.1
Barco wePresent WiPG-1000Pfirmware 2.3.0.10
Barco wePresent WiPG-1600Wfirmware before 2.4.1.19
Extron ShareLink 200firmware 2.0.3.4
Extron ShareLink 250firmware 2.0.3.4
Teq AV IT WIPS710firmware 1.1.0.7
SHARP PN-L703WAfirmware 1.4.2.3
Optoma WPS-Profirmware 1.0.0.5
Blackbox HD Wireless Presentation Systemfirmware 1.0.0.5
InFocus LiteShow3firmware 1.0.16
InFocus LiteShow4firmware 2.0.0.7
Estimated exposure
largeon the order of tens of thousands of deployed gateways, with likely thousands to tens of thousands internet-exposed (estimate) — These conference-room wireless presentation gateways are widely deployed in corporate, education, and government AV estates, and because the affected products are OEM variants of one shared platform, public internet scans of such embedded…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CISA Known Exploited Vulnerability
Affected
Crestron Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
crestronbarcoextronteqavitsharpoptomablackboxinfocus
Products
am-100 firmware, am-101 firmware, wepresent wipg-1000p firmware, wepresent wipg-1600w firmware, sharelink 200 firmware, sharelink 250 firmware, wips710 firmware, pn-l703wa firmware, wps-pro firmware, hd wireless presentation system firmware, liteshow3 firmware, liteshow4 firmware
Weakness
CWE-79, CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.