crestron security advisories
7 threat alerts tracking vulnerabilities and security advisories that affect crestron products.
Vulnios monitors crestron CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent crestron security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2019-18184 — crestron — dmc-stro_firmware, dmc-stro
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
criticalCVE-2019-18184Critical Vulnerability: CVE-2016-5669 — crestron — dm-txrx-100-str_firmware, dm-txrx-100-str
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL Test Certification Authority, which makes it easier
criticalCVE-2016-5669Critical Vulnerability: CVE-2016-5640 — crestron — airmedia_am-100_firmware, airmedia_am-100
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in th
criticalCVE-2016-5640Critical Vulnerability: CVE-2016-5667 — crestron — dm-txrx-100-str_firmware, dm-txrx-100-str
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct request to a page other than index.html.
criticalCVE-2016-5667Critical Vulnerability: CVE-2016-5668 — crestron — dm-txrx-100-str_firmware, dm-txrx-100-str
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call.
criticalCVE-2016-5668Critical Vulnerability: CVE-2016-5670 — crestron — dm-txrx-100-str_firmware, dm-txrx-100-str
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via
criticalCVE-2016-5670Critical Vulnerability: CVE-2016-5666 — crestron — dm-txrx-100-str_firmware, dm-txrx-100-str
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote attackers to obtain access by setting the value of objr
criticalCVE-2016-5666
Track crestron exposure across your environment
Vulnios automatically cross-references your asset inventory against new crestron CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan