Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-3910

34
FAUCET Score

CVE-2019-3910 is an authentication bypass vulnerability in the web interface of Crestron AM-100 devices running firmware older than version 1.6.0.2. This critical vulnerability (CVSS 9.1) allows unauthenticated remote attackers to access administrative functions like configuring update sources and rebooting the device, leading to high impact on integrity and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.6.0.2CPE matchmatch criteria
cpe:2.3:o:crestron:airmedia_am-100_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.1CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.0

Exploit Intelligence

EPSS Score
8.56%
Probability of exploitation in next 30 days
EPSS Percentile
94.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0856 is in the 90th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

dogukanurkervendor investigatingvia llm_extracted
posthogvendor investigatingvia llm_extracted
qlikvendor investigatingvia llm_extracted

Vendor Advisories (3)

dogukanurkerllm-dogukanurker-ae67cf4efea7d26eCRITICAL

[R1] Crestron AM-100 Authentication Bypass

Jan 10, 2019
qlikllm-qlik-9e93329b2db27311CRITICAL

[R1] Crestron AM-100 Authentication Bypass

Jan 10, 2019
posthogllm-posthog-f4c448e1e660861aCRITICAL

[R1] Crestron AM-100 Authentication Bypass

Jan 10, 2019

References

tenable.com / security/research/tra-2019-02
ExploitThird Party Advisory