crestron CVE Vulnerabilities & Metrics

Focus on crestron vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About crestron Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with crestron. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total crestron CVEs: 39
Earliest CVE date: 03 Aug 2016, 01:59 UTC
Latest CVE date: 23 Jan 2024, 20:15 UTC

Latest CVE reference: CVE-2023-6926

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical crestron CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.09

Max CVSS: 10.0

Critical CVEs (≥9): 12

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 12
7.0-8.9 6
9.0-10.0 12

CVSS Distribution Chart

Top 5 Highest CVSS crestron CVEs

These are the five CVEs with the highest CVSS scores for crestron, sorted by severity first and recency.

All CVEs for crestron

CVE-2023-6926 crestron vulnerability CVSS: 0 23 Jan 2024, 20:15 UTC

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.

CVE-2023-38405 crestron vulnerability CVSS: 0 17 Jul 2023, 21:15 UTC

On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.

CVE-2022-40298 crestron vulnerability CVSS: 0 23 Sep 2022, 00:15 UTC

Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.

CVE-2022-34102 crestron vulnerability CVSS: 0 13 Sep 2022, 22:15 UTC

Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.

CVE-2022-34101 crestron vulnerability CVSS: 0 13 Sep 2022, 22:15 UTC

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.

CVE-2022-34100 crestron vulnerability CVSS: 0 13 Sep 2022, 19:15 UTC

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation.

CVE-2022-23178 crestron vulnerability CVSS: 10.0 15 Jan 2022, 15:17 UTC

An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.

CVE-2020-16839 crestron vulnerability CVSS: 5.0 30 Jul 2021, 14:15 UTC

On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.

CVE-2019-18184 crestron vulnerability CVSS: 10.0 27 Nov 2019, 16:15 UTC

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

CVE-2019-3939 crestron vulnerability CVSS: 7.5 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.

CVE-2019-3938 crestron vulnerability CVSS: 2.1 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is encrypted using the awenc binary. The same binary can be used to decrypt any configuration file since all the encryption logic is hard coded. A local attacker can use this vulnerability to gain access to devices username and passwords.

CVE-2019-3937 crestron vulnerability CVSS: 2.1 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to recover sensitive data.

CVE-2019-3936 crestron vulnerability CVSS: 5.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The request will force the slideshow to transition into a "stopped" state. A remote, unauthenticated attacker can use this vulnerability to stop an active slideshow.

CVE-2019-3935 crestron vulnerability CVSS: 6.4 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this vulnerability to start, stop, and disconnect active slideshows.

CVE-2019-3934 crestron vulnerability CVSS: 5.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulnerability to download the current slide image without knowing the access code.

CVE-2019-3933 crestron vulnerability CVSS: 5.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP. A remote, unauthenticated attacker can use this vulnerability to watch a slideshow without knowing the access code.

CVE-2019-3932 crestron vulnerability CVSS: 7.5 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.

CVE-2019-3931 crestron vulnerability CVSS: 9.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vulnerability to upload files to the device and ultimately execute code as root.

CVE-2019-3930 crestron vulnerability CVSS: 10.0 30 Apr 2019, 21:29 UTC

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to a stack buffer overflow in libAwgCgi.so's PARSERtoCHAR function. A remote, unauthenticated attacker can use this vulnerability to execute arbitrary code as root via a crafted request to the return.cgi endpoint.

CVE-2019-3929 crestron vulnerability CVSS: 10.0 30 Apr 2019, 21:29 UTC

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CVE-2019-3928 crestron vulnerability CVSS: 5.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.100.3.2.7.4 OIDs. A remote, unauthenticated attacker can use this vulnerability to access a restricted presentation or to become the presenter.

CVE-2019-3927 crestron vulnerability CVSS: 5.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to change the admin or moderator user's password and gain access to restricted areas on the HTTP interface.

CVE-2019-3926 crestron vulnerability CVSS: 10.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CVE-2019-3925 crestron vulnerability CVSS: 10.0 30 Apr 2019, 21:29 UTC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CVE-2019-3910 crestron vulnerability CVSS: 8.5 18 Jan 2019, 18:29 UTC

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

CVE-2018-10630 crestron vulnerability CVSS: 10.0 10 Aug 2018, 19:29 UTC

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.

CVE-2017-16710 crestron vulnerability CVSS: 3.5 11 Jul 2018, 16:29 UTC

Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2017-16709 crestron vulnerability CVSS: 6.5 11 Jul 2018, 16:29 UTC

Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors.

CVE-2018-5553 crestron vulnerability CVSS: 10.0 10 Jul 2018, 16:29 UTC

The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.

CVE-2018-11229 crestron vulnerability CVSS: 7.5 08 Jun 2018, 01:29 UTC

Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP).

CVE-2018-11228 crestron vulnerability CVSS: 10.0 08 Jun 2018, 01:29 UTC

Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP).

CVE-2016-5671 crestron vulnerability CVSS: 6.8 03 Aug 2016, 01:59 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities on Crestron Electronics DM-TXRX-100-STR devices with firmware through 1.3039.00040 allow remote attackers to hijack the authentication of arbitrary users.

CVE-2016-5670 crestron vulnerability CVSS: 10.0 03 Aug 2016, 01:59 UTC

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via the web management interface.

CVE-2016-5669 crestron vulnerability CVSS: 5.0 03 Aug 2016, 01:59 UTC

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL Test Certification Authority, which makes it easier for remote attackers to conduct man-in-the-middle attacks against HTTPS sessions by leveraging the certificate's trust relationship.

CVE-2016-5668 crestron vulnerability CVSS: 7.5 03 Aug 2016, 01:59 UTC

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call.

CVE-2016-5667 crestron vulnerability CVSS: 7.5 03 Aug 2016, 01:59 UTC

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct request to a page other than index.html.

CVE-2016-5666 crestron vulnerability CVSS: 5.0 03 Aug 2016, 01:59 UTC

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote attackers to obtain access by setting the value of objresp.authenabled to 1.

CVE-2016-5640 crestron vulnerability CVSS: 10.0 03 Aug 2016, 01:59 UTC

Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.

CVE-2016-5639 crestron vulnerability CVSS: 5.0 03 Aug 2016, 01:59 UTC

Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.