ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-50960
A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <=

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

NVD description · AI analysis pending
7.22% PoC ×2
  • extron smp 111 firmware
  • extron smp 351 firmware
  • extron smp 352 firmware
  • +1 more
CVE-2019-3930
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to a stack buffer overflow in libAwgCgi.so's PARSERtoCHAR function. A remote, unauthenticated attacker can use this vulnerability to execute arbitrary code as root via a crafted request to the return.cgi endpoint.

NVD description · AI analysis pending
9.87% PoC
  • crestron am-100 firmware
  • crestron am-101 firmware
  • crestron wepresent wipg-1000p firmware
  • +1 more
CVE-2019-3929
Unauthenticated root command injection in multi-vendor wireless presentation gateways

CVE-2019-3929 is an unauthenticated OS command injection in the file_transfer.cgi HTTP endpoint of the embedded web server used by a family of wireless presentation gateways. A remote attacker who can reach the device's web interface sends a crafted request to file_transfer.cgi, causing arbitrary operating system commands to run as root. Successful exploitation yields full compromise of the device, which typically sits inside the corporate network and can be used as a pivot into internal systems. Affected products span Crestron (AM-100, AM-101), Barco wePresent (WiPG-1000P, WiPG-1600W), Extron ShareLink 200/250, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, and InFocus LiteShow3/LiteShow4 — most of which are OEM variants of the same platform. The flaw has a public proof of concept (Exploit-DB 46786, Tenable TRA-2019-20), a 99% EPSS score, and is listed in CISA's Known Exploited Vulnerabilities catalog as of 2022-04-15, indicating exploitation in the wild.

Do: Apply vendor firmware updates per CISA's required action — for Barco wePresent WiPG-1600W this means 2.4.1.19 or later, and owners of the other listed models should obtain the fixed firmware from each vendor's advisory (Tenable TRA-2019-20 / Exploit-DB 46786). Until patched, restrict the devices' web interface (including the file_transfer.cgi endpoint) from internet exposure and limit access to trusted management or presentation VLANs. Check device logs and network traffic for unexpected requests to file_transfer.cgi, and treat any internet-facing unit as potentially compromised since the flaw allows unauthenticated root-level access.

9.899% KEV PoC ×2
  • Crestron AM-100 firmware 1.6.0.2
  • Crestron AM-101 firmware 2.7.0.1
  • Barco wePresent WiPG-1000P firmware 2.3.0.10
  • +9 more
largeon the order of tens of thousands of deployed gateways, with likely thousands to tens of thousands internet-exposed (estimate)