Crestron records
40 published records for vendor crestron.
Researcher profile
- Entered KEV
- 1 · 2.5%
- Weaponized
- 2 · 5%
- Pre-auth RCE
- 9
- With a fix record
- 0%
- Median publish → KEV
- 1081 days
Recurring classes
- CWE-284 Improper Access Control7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-287 Improper Authentication2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2019-3929Weaponized | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-79 | Critical9.8 | KEV | 99.0% | Apr 30, 2019 |
62This week | CVE-2022-23178Proof of concept | An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices.crestron · hd-md4x2-4k-e firmware · CWE-287 | Critical9.8 | — | 75.2% | Jan 15, 2022 |
50Plan | CVE-2017-16709Weaponized | Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated adminicrestron · airmedia am-100 firmware | High7.2 | — | 72.0% | Jul 11, 2018 |
50Plan | CVE-2019-3932No exploit | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password crestron · am-100 firmware · CWE-249 | Critical9.8 | — | 36.3% | Apr 30, 2019 |
44Plan | CVE-2016-5640Proof of concept | Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attacrestron · airmedia am-100 firmware · CWE-77 | Critical9.8 | — | 17.7% | Aug 2, 2016 |
42Plan | CVE-2018-10630No exploit | For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication dicrestron · tsw-x60 firmware · CWE-284 | Critical9.8 | — | 10.9% | Aug 10, 2018 |
41Plan | CVE-2019-18184No exploit | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.crestron · dmc-stro firmware · CWE-78 | Critical9.8 | — | 8.1% | Nov 27, 2019 |
41Plan | CVE-2018-11228No exploit | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote codecrestron · crestron toolbox protocol firmware · CWE-94 | Critical9.8 | — | 7.5% | Jun 7, 2018 |
41Plan | CVE-2019-3930No exploit | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-121 | Critical9.8 | — | 7.0% | Apr 30, 2019 |
41Plan | CVE-2019-3926No exploit | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1crestron · am-100 firmware · CWE-79 | Critical9.8 | — | 6.9% | Apr 30, 2019 |
41Plan | CVE-2019-3925No exploit | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1crestron · am-100 firmware · CWE-79 | Critical9.8 | — | 6.9% | Apr 30, 2019 |
41Plan | CVE-2018-11229No exploit | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote codecrestron · crestron toolbox protocol firmware · CWE-78 | Critical9.8 | — | 5.6% | Jun 7, 2018 |
40Plan | CVE-2016-5668No exploit | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change secrestron · dm-txrx-100-str firmware | Critical9.8 | — | 4.4% | Aug 2, 2016 |
40Plan | CVE-2016-5667No exploit | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct crestron · dm-txrx-100-str firmware | Critical9.8 | — | 4.4% | Aug 2, 2016 |
40Plan | CVE-2016-5666No exploit | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows recrestron · dm-txrx-100-str firmware | Critical9.8 | — | 4.2% | Aug 2, 2016 |
40Plan | CVE-2016-5670No exploit | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, whicrestron · dm-txrx-100-str firmware · CWE-255 | Critical9.8 | — | 3.2% | Aug 2, 2016 |
40Plan | CVE-2019-3939No exploit | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the wcrestron · am-100 firmware · CWE-16 | Critical9.8 | — | 2.8% | Apr 30, 2019 |
40Plan | CVE-2018-5553No exploit | Crestron DGE-100 Console Command Injection (FIXED)crestron · dge-100 firmware · CWE-78 | Critical9.8 | — | 2.5% | Jul 10, 2018 |
40Plan | CVE-2019-3927No exploit | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the icrestron · am-100 firmware · CWE-284 | Critical9.8 | — | 2.2% | Apr 30, 2019 |
39Monitor | CVE-2019-3910No exploit | Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script.crestron · airmedia am-100 firmware | Critical9.1 | — | 8.6% | Jan 18, 2019 |
39Monitor | CVE-2016-5669No exploit | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an crestron · dm-txrx-100-str firmware | Critical9.8 | — | 1.6% | Aug 2, 2016 |
37Monitor | CVE-2019-3931No exploit | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via craftecrestron · am-100 firmware · CWE-88 | High8.8 | — | 5.8% | Apr 30, 2019 |
37Monitor | CVE-2019-3935No exploit | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP crestron · am-100 firmware · CWE-284 | Critical9.1 | — | 3.3% | Apr 30, 2019 |
36Monitor | CVE-2016-5639Proof of concept | Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attaccrestron · airmedia am-100 firmware · CWE-22 | High7.5 | — | 20.8% | Aug 2, 2016 |
36Monitor | CVE-2018-13341Proof of concept | Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts mcrestron · tsw-x60 firmware | High8.8 | — | 3.7% | Aug 10, 2018 |
- CVE-2019-392999Now
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
CriticalCVSS 9.8KEVWeaponizedEPSS 99%crestron · am-100 firmwareApr 30, 2019
- CVE-2022-2317862This week
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices.
CriticalCVSS 9.8Proof of conceptEPSS 75%crestron · hd-md4x2-4k-e firmwareJan 15, 2022
- CVE-2017-1670950Plan
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated admini
HighCVSS 7.2WeaponizedEPSS 72%crestron · airmedia am-100 firmwareJul 11, 2018
- CVE-2019-393250Plan
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password
CriticalCVSS 9.8No exploitEPSS 36%crestron · am-100 firmwareApr 30, 2019
- CVE-2016-564044Plan
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote atta
CriticalCVSS 9.8Proof of conceptEPSS 18%crestron · airmedia am-100 firmwareAug 2, 2016
- CVE-2018-1063042Plan
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication di
CriticalCVSS 9.8No exploitEPSS 11%crestron · tsw-x60 firmwareAug 10, 2018
- CVE-2019-1818441Plan
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
CriticalCVSS 9.8No exploitEPSS 8%crestron · dmc-stro firmwareNov 27, 2019
- CVE-2018-1122841Plan
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code
CriticalCVSS 9.8No exploitEPSS 7%crestron · crestron toolbox protocol firmwareJun 7, 2018
- CVE-2019-393041Plan
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
CriticalCVSS 9.8No exploitEPSS 7%crestron · am-100 firmwareApr 30, 2019
- CVE-2019-392641Plan
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1
CriticalCVSS 9.8No exploitEPSS 7%crestron · am-100 firmwareApr 30, 2019
- CVE-2019-392541Plan
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1
CriticalCVSS 9.8No exploitEPSS 7%crestron · am-100 firmwareApr 30, 2019
- CVE-2018-1122941Plan
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code
CriticalCVSS 9.8No exploitEPSS 6%crestron · crestron toolbox protocol firmwareJun 7, 2018
- CVE-2016-566840Plan
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change se
CriticalCVSS 9.8No exploitEPSS 4%crestron · dm-txrx-100-str firmwareAug 2, 2016
- CVE-2016-566740Plan
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct
CriticalCVSS 9.8No exploitEPSS 4%crestron · dm-txrx-100-str firmwareAug 2, 2016
- CVE-2016-566640Plan
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows re
CriticalCVSS 9.8No exploitEPSS 4%crestron · dm-txrx-100-str firmwareAug 2, 2016
- CVE-2016-567040Plan
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, whi
CriticalCVSS 9.8No exploitEPSS 3%crestron · dm-txrx-100-str firmwareAug 2, 2016
- CVE-2019-393940Plan
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the w
CriticalCVSS 9.8No exploitEPSS 3%crestron · am-100 firmwareApr 30, 2019
- CVE-2018-555340Plan
Crestron DGE-100 Console Command Injection (FIXED)
CriticalCVSS 9.8No exploitEPSS 2%crestron · dge-100 firmwareJul 10, 2018
- CVE-2019-392740Plan
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the i
CriticalCVSS 9.8No exploitEPSS 2%crestron · am-100 firmwareApr 30, 2019
- CVE-2019-391039Monitor
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script.
CriticalCVSS 9.1No exploitEPSS 9%crestron · airmedia am-100 firmwareJan 18, 2019
- CVE-2016-566939Monitor
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an
CriticalCVSS 9.8No exploitEPSS 2%crestron · dm-txrx-100-str firmwareAug 2, 2016
- CVE-2019-393137Monitor
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafte
HighCVSS 8.8No exploitEPSS 6%crestron · am-100 firmwareApr 30, 2019
- CVE-2019-393537Monitor
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP
CriticalCVSS 9.1No exploitEPSS 3%crestron · am-100 firmwareApr 30, 2019
- CVE-2016-563936Monitor
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attac
HighCVSS 7.5Proof of conceptEPSS 21%crestron · airmedia am-100 firmwareAug 2, 2016
- CVE-2018-1334136Monitor
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts m
HighCVSS 8.8Proof of conceptEPSS 4%crestron · tsw-x60 firmwareAug 10, 2018