Loading HuntDB...

Crestron Multiple Products Command Injection Vulnerability

Added April 15, 2022 Due May 6, 2022 CVE-2019-3929
Overdue Crestron / Multiple Products CWE-79

Description

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
5 months, 2 weeks ago