ZeroHour

Vulnerabilities

40 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-6926
There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escal

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.

NVD description · AI analysis pending
7.8<1%
  • crestron am-300 firmware
CVE-2023-38405
On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.

On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.

NVD description · AI analysis pending
7.5<1%
  • crestron cp3n 6505417 firmware
  • crestron cp3 6504877 firmware
  • crestron cp3-gv 6506034 firmware
CVE-2022-40298
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Wind

Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.

NVD description · AI analysis pending
8.8<1%
  • crestron airmedia
CVE-2022-34100
+2 in the same advisory: …34102 …34101
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command pr

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation.

NVD description · AI analysis pending
8.8
group max
1%
  • crestron airmedia
CVE-2022-23178
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices.

An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.

NVD description · AI analysis pending
9.875% PoC
  • crestron hd-md4x2-4k-e firmware
CVE-2020-16839
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSoc

On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.

NVD description · AI analysis pending
7.51%
  • crestron dm-nvx-dir-80 firmware
  • crestron dm-nvx-dir-160 firmware
  • crestron dm-nvx-dir-ent firmware
CVE-2019-18184
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

NVD description · AI analysis pending
9.88% PoC
  • crestron dmc-stro firmware
CVE-2019-3932
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi.

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.

NVD description · AI analysis pending
9.8
group max
36% PoC
  • crestron am-100 firmware
  • crestron am-101 firmware
CVE-2019-3929
Unauthenticated root command injection in multi-vendor wireless presentation gateways

CVE-2019-3929 is an unauthenticated OS command injection in the file_transfer.cgi HTTP endpoint of the embedded web server used by a family of wireless presentation gateways. A remote attacker who can reach the device's web interface sends a crafted request to file_transfer.cgi, causing arbitrary operating system commands to run as root. Successful exploitation yields full compromise of the device, which typically sits inside the corporate network and can be used as a pivot into internal systems. Affected products span Crestron (AM-100, AM-101), Barco wePresent (WiPG-1000P, WiPG-1600W), Extron ShareLink 200/250, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, and InFocus LiteShow3/LiteShow4 — most of which are OEM variants of the same platform. The flaw has a public proof of concept (Exploit-DB 46786, Tenable TRA-2019-20), a 99% EPSS score, and is listed in CISA's Known Exploited Vulnerabilities catalog as of 2022-04-15, indicating exploitation in the wild.

Do: Apply vendor firmware updates per CISA's required action — for Barco wePresent WiPG-1600W this means 2.4.1.19 or later, and owners of the other listed models should obtain the fixed firmware from each vendor's advisory (Tenable TRA-2019-20 / Exploit-DB 46786). Until patched, restrict the devices' web interface (including the file_transfer.cgi endpoint) from internet exposure and limit access to trusted management or presentation VLANs. Check device logs and network traffic for unexpected requests to file_transfer.cgi, and treat any internet-facing unit as potentially compromised since the flaw allows unauthenticated root-level access.

9.899% KEV PoC ×2
  • Crestron AM-100 firmware 1.6.0.2
  • Crestron AM-101 firmware 2.7.0.1
  • Barco wePresent WiPG-1000P firmware 2.3.0.10
  • +9 more
largeon the order of tens of thousands of deployed gateways, with likely thousands to tens of thousands internet-exposed (estimate)
CVE-2019-3910
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script.

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

NVD description · AI analysis pending
9.19% PoC
  • crestron airmedia am-100 firmware
CVE-2018-10630
+1 in the same advisory: …13341
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.

NVD description · AI analysis pending
9.8
group max
11%
  • crestron tsw-x60 firmware
  • crestron mc3 firmware
CVE-2017-16709
+1 in the same advisory: …16710
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute

Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors.

NVD description · AI analysis pending
7.2
group max
72%
  • crestron airmedia am-100 firmware
  • crestron airmedia am-101 firmware
CVE-2018-5553
The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 a

The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.

NVD description · AI analysis pending
9.82%
  • crestron dge-100 firmware
  • crestron dm-dge-200-c firmware
  • crestron ts-1542-c firmware
CVE-2018-11228
+1 in the same advisory: …11229
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bas

Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP).

NVD description · AI analysis pending
9.87%
  • crestron crestron toolbox protocol firmware
CVE-2016-5668
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON AP

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call.

NVD description · AI analysis pending
9.8
group max
4%
  • crestron dm-txrx-100-str firmware
CVE-2016-5640
+1 in the same advisory: …5639
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arb

Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.

NVD description · AI analysis pending
9.8
group max
18%
  • crestron airmedia am-100 firmware