← KEV catalog
CISA known exploited vulnerability

CVE-2019-3929

Crestron Multiple Products Command Injection Vulnerability

SOURCE FACT

Crestron · Multiple Products

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2019-3929

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?