Crestron Electronics, Inc.

First CVE: May 6, 2025Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
4.0
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Crestron Electronics, Inc. as a CNA, 0.0% affect products that Crestron Electronics, Inc. develops as a vendor.

100.0%
Self-reported: 0Third-party: 8

Of all the CVEs published that affect products developed by Crestron Electronics, Inc., 0.0% are self-published by Crestron Electronics, Inc. as a CNA.

100.0%
Self-published: 0Published by other CNAs: 40

Trends Over Time

The number and severity of CVEs published by Crestron Electronics, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2025
14 months ago
Most Recent CVE
May 5, 2026
80 days ago

Top CVEs

All CVEs published by Crestron Electronics, Inc. as a CNA, regardless of affected vendor or product.

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure netw
May 6, 202510.028NONO
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument.  A third party researcher Eugene Lim had discovered vul
May 5, 20267.427NONO
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCRE
Sep 3, 20258.626NONO
266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
May 6, 20258.723NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCR
Sep 9, 20256.822NONO
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets
Sep 9, 20255.920NONO
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Images in Crestron Automate VX is
May 6, 20255.117NONO
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is rec
May 6, 20255.316NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA8 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High5 (62.5%)
None1 (12.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Crestron Electronics, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Crestron Electronics, Inc. as a CNA — matched by CVE ID, not by organization name.

Top CWEs