CVE-2019-3929

Crestron Multiple Products Command Injection Vulnerability

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root. Vendor/Product: Crestron Multiple Products. Added to CISA KEV 2022-04-15; required action: Apply updates per vendor instructions.

Category: Vulnerability, Known Exploited