Crestron Electronics, Inc.
Self-Reporting Analysis
Of all the CVEs published by Crestron Electronics, Inc. as a CNA, 0.0% affect products that Crestron Electronics, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Crestron Electronics, Inc., 0.0% are self-published by Crestron Electronics, Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Crestron Electronics, Inc. over time
Top CVEs
All CVEs published by Crestron Electronics, Inc. as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47419CRITICAL Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.
The device allows Web UI and API access over non-secure netw | May 6, 2025 | 10.0 | 28 | NO | NO |
CVE-2026-7865HIGH A hidden console command is vulnerable to command injection
flaw when control characters are passed to its second argument.
A third party researcher Eugene Lim had discovered vul | May 5, 2026 | 7.4 | 27 | NO | NO |
CVE-2025-47421HIGH Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCRE | Sep 3, 2025 | 8.6 | 26 | NO | NO |
CVE-2025-47420HIGH 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | May 6, 2025 | 8.7 | 23 | NO | NO |
CVE-2025-47415MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCR | Sep 9, 2025 | 6.8 | 22 | NO | NO |
CVE-2025-47416MEDIUM A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets | Sep 9, 2025 | 5.9 | 20 | NO | NO |
CVE-2025-47417MEDIUM Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse.
When Enable Debug Images in Crestron Automate VX is | May 6, 2025 | 5.1 | 17 | NO | NO |
CVE-2025-47418MEDIUM Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse.
There is no visible indication when the system is rec | May 6, 2025 | 5.3 | 16 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Crestron Electronics, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Crestron Electronics, Inc. as a CNA — matched by CVE ID, not by organization name.