← Back

Crestron

crestron

40 CVEs • 58 products

Products (58)

Click to collapse
Toggle
Airmedia
airmedia
Mc3 Firmware
mc3_firmware
Dmc Str
dmc-str
Tsw 1060
tsw-1060
Tsw 1060 Nc
tsw-1060-nc
Tsw 560
tsw-560
Tsw 560 Nc
tsw-560-nc
Tsw 760
tsw-760
Tsw 760 Nc
tsw-760-nc
Dge 100
dge-100
Dm Dge 200 C
dm-dge-200-c
Ts 1542 C
ts-1542-c
Tsw 1060 B S
tsw-1060-b-s
Tsw 1060 W S
tsw-1060-w-s
Tsw 560 B S
tsw-560-b-s
Tsw 560 W S
tsw-560-w-s
Tsw 760 B S
tsw-760-b-s
Tsw 760 W S
tsw-760-w-s
Mc3
mc3
Am 100
am-100
Am 101
am-101
Dmc Stro
dmc-stro
Dm Nvx Dir 80
dm-nvx-dir-80
Hd Md4x2 4k E
hd-md4x2-4k-e
Cp3n 6505417
cp3n_6505417
Cp3 6504877
cp3_6504877
Am 300
am-300

CVEs (40)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Crestron
1Am 300 Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.
1Crestron
3Cp3 Gv 6506034 Firmware
Cp3 6504877 FirmwareCp3n 6505417 Firmware
Jun 17, 2026
Jul 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.
1Crestron
1Airmedia
Jun 17, 2026
Sep 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can...Show more
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.Show less
1Crestron
1Airmedia
Jun 17, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt...Show more
Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.Show less
1Crestron
1Airmedia
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.
1Crestron
1Airmedia
Jun 17, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installati...Show more
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation.Show less
1Crestron
1Hd Md4x2 4k E Firmware
Jun 17, 2026
Jan 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate...Show more
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.Show less
1Crestron
3Dm Nvx Dir 160 Firmware
Dm Nvx Dir 80 FirmwareDm Nvx Dir Ent Firmware
Jun 17, 2026
Jul 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
1Crestron
1Dmc Stro Firmware
Jun 17, 2026
Nov 27, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to g...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is encrypted using the awenc binary. The same binary can be used to decrypt any configuration file since all the encryption logic is hard coded. A local attacker can use this vulnerability to gain access to devices username and passwords.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use thi...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to recover sensitive data.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The request will force the slideshow to transition into a "stopped" state....Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The request will force the slideshow to transition into a "stopped" state. A remote, unauthenticated attacker can use this vulnerability to stop an active slideshow.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this vulnerability to start, stop, and disconnect active slideshows.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulne...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulnerability to download the current slide image without knowing the access code.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP. A remote, unauthenticated attacker can use this...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP. A remote, unauthenticated attacker can use this vulnerability to watch a slideshow without knowing the access code.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.Show less
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vul...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vulnerability to upload files to the device and ultimately execute code as root.Show less
8Barco
BlackboxCrestron+5 more
12Am 100 Firmware
Am 101 FirmwareHd Wireless Presentation System Firmware+9 more
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV...Show more
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to a stack buffer overflow in libAwgCgi.so's PARSERtoCHAR function. A remote, unauthenticated attacker can use this vulnerability to execute arbitrary code as root via a crafted request to the return.cgi endpoint.Show less
8Barco
BlackboxCrestron+5 more
12Am 100 Firmware
Am 101 FirmwareHd Wireless Presentation System Firmware+9 more
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV...Show more
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.Show less