Skip to content
Noroxi

Crestron records

40 published records for vendor crestron.

All records

40 records
  • The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    crestron · am-100 firmwareApr 30, 2019

  • CVE-2022-23178
    62This week

    An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices.

    CriticalCVSS 9.8Proof of conceptEPSS 75%

    crestron · hd-md4x2-4k-e firmwareJan 15, 2022

  • Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated admini

    HighCVSS 7.2WeaponizedEPSS 72%

    crestron · airmedia am-100 firmwareJul 11, 2018

  • Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password

    CriticalCVSS 9.8No exploitEPSS 36%

    crestron · am-100 firmwareApr 30, 2019

  • Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote atta

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    crestron · airmedia am-100 firmwareAug 2, 2016

  • For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication di

    CriticalCVSS 9.8No exploitEPSS 11%

    crestron · tsw-x60 firmwareAug 10, 2018

  • Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

    CriticalCVSS 9.8No exploitEPSS 8%

    crestron · dmc-stro firmwareNov 27, 2019

  • Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code

    CriticalCVSS 9.8No exploitEPSS 7%

    crestron · crestron toolbox protocol firmwareJun 7, 2018

  • The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1

    CriticalCVSS 9.8No exploitEPSS 7%

    crestron · am-100 firmwareApr 30, 2019

  • Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1

    CriticalCVSS 9.8No exploitEPSS 7%

    crestron · am-100 firmwareApr 30, 2019

  • Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1

    CriticalCVSS 9.8No exploitEPSS 7%

    crestron · am-100 firmwareApr 30, 2019

  • Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code

    CriticalCVSS 9.8No exploitEPSS 6%

    crestron · crestron toolbox protocol firmwareJun 7, 2018

  • Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change se

    CriticalCVSS 9.8No exploitEPSS 4%

    crestron · dm-txrx-100-str firmwareAug 2, 2016

  • Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct

    CriticalCVSS 9.8No exploitEPSS 4%

    crestron · dm-txrx-100-str firmwareAug 2, 2016

  • Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows re

    CriticalCVSS 9.8No exploitEPSS 4%

    crestron · dm-txrx-100-str firmwareAug 2, 2016

  • Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, whi

    CriticalCVSS 9.8No exploitEPSS 3%

    crestron · dm-txrx-100-str firmwareAug 2, 2016

  • Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the w

    CriticalCVSS 9.8No exploitEPSS 3%

    crestron · am-100 firmwareApr 30, 2019

  • Crestron DGE-100 Console Command Injection (FIXED)

    CriticalCVSS 9.8No exploitEPSS 2%

    crestron · dge-100 firmwareJul 10, 2018

  • Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the i

    CriticalCVSS 9.8No exploitEPSS 2%

    crestron · am-100 firmwareApr 30, 2019

  • CVE-2019-3910
    39Monitor

    Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script.

    CriticalCVSS 9.1No exploitEPSS 9%

    crestron · airmedia am-100 firmwareJan 18, 2019

  • CVE-2016-5669
    39Monitor

    Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an

    CriticalCVSS 9.8No exploitEPSS 2%

    crestron · dm-txrx-100-str firmwareAug 2, 2016

  • CVE-2019-3931
    37Monitor

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafte

    HighCVSS 8.8No exploitEPSS 6%

    crestron · am-100 firmwareApr 30, 2019

  • CVE-2019-3935
    37Monitor

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP

    CriticalCVSS 9.1No exploitEPSS 3%

    crestron · am-100 firmwareApr 30, 2019

  • CVE-2016-5639
    36Monitor

    Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attac

    HighCVSS 7.5Proof of conceptEPSS 21%

    crestron · airmedia am-100 firmwareAug 2, 2016

  • Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts m

    HighCVSS 8.8Proof of conceptEPSS 4%

    crestron · tsw-x60 firmwareAug 10, 2018