Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2019-3929

Crestron | Multiple ProductsAdded 2022-04-15Remediation Deadline 2022-05-06

Crestron Multiple Products Command Injection Vulnerability

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-79

References