Vulnerabilities
40 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-6926 | There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escal There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2023-38405 | On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash. On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-40298 | Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Wind Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-34100 | A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command pr A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2022-23178 | An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields. NVD description · AI analysis pending | 9.8 | 75% | PoC |
| — | |
| CVE-2020-16839 | On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSoc On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2019-18184 | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. NVD description · AI analysis pending | 9.8 | 8% | PoC |
| — | |
| CVE-2019-3932 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge. NVD description · AI analysis pending | 9.8 group max | 36% | PoC |
| — | |
| CVE-2019-3929 | Unauthenticated root command injection in multi-vendor wireless presentation gateways CVE-2019-3929 is an unauthenticated OS command injection in the file_transfer.cgi HTTP endpoint of the embedded web server used by a family of wireless presentation gateways. A remote attacker who can reach the device's web interface sends a crafted request to file_transfer.cgi, causing arbitrary operating system commands to run as root. Successful exploitation yields full compromise of the device, which typically sits inside the corporate network and can be used as a pivot into internal systems. Affected products span Crestron (AM-100, AM-101), Barco wePresent (WiPG-1000P, WiPG-1600W), Extron ShareLink 200/250, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, and InFocus LiteShow3/LiteShow4 — most of which are OEM variants of the same platform. The flaw has a public proof of concept (Exploit-DB 46786, Tenable TRA-2019-20), a 99% EPSS score, and is listed in CISA's Known Exploited Vulnerabilities catalog as of 2022-04-15, indicating exploitation in the wild. Do: Apply vendor firmware updates per CISA's required action — for Barco wePresent WiPG-1600W this means 2.4.1.19 or later, and owners of the other listed models should obtain the fixed firmware from each vendor's advisory (Tenable TRA-2019-20 / Exploit-DB 46786). Until patched, restrict the devices' web interface (including the file_transfer.cgi endpoint) from internet exposure and limit access to trusted management or presentation VLANs. Check device logs and network traffic for unexpected requests to file_transfer.cgi, and treat any internet-facing unit as potentially compromised since the flaw allows unauthenticated root-level access. | 9.8 | 99% | KEV PoC ×2 |
| largeon the order of tens of thousands of deployed gateways, with likely thousands to tens of thousands internet-exposed (estimate) | |
| CVE-2019-3910 | Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device. NVD description · AI analysis pending | 9.1 | 9% | PoC |
| — | |
| CVE-2018-10630 +1 in the same advisory: …13341 | For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open. NVD description · AI analysis pending | 9.8 group max | 11% |
| — | ||
| CVE-2017-16709 +1 in the same advisory: …16710 | Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors. NVD description · AI analysis pending | 7.2 group max | 72% |
| — | ||
| CVE-2018-5553 | The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 a The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2018-11228 +1 in the same advisory: …11229 | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bas Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP). NVD description · AI analysis pending | 9.8 | 7% |
| — | ||
| CVE-2016-5668 | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON AP Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call. NVD description · AI analysis pending | 9.8 group max | 4% |
| — | ||
| CVE-2016-5640 +1 in the same advisory: …5639 | Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arb Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter. NVD description · AI analysis pending | 9.8 group max | 18% |
| — |