CVE-2025-47416 is a medium-severity vulnerability (CVSS 5.9) affecting discontinued TSW-760 and TSW-1060 devices running specific firmware versions. It allows an authenticated attacker to execute arbitrary files by manipulating the alphabetical order of command files in the /dev/shm/symproc/c directory, which is processed by the ConsoleFindCommandMatchList function. This vulnerability has a high attack complexity and requires high privileges, but if exploited, it could lead to unauthorized execution of attacker-defined files. There are no known exploits in the wild, no public exploit code, and minimal community discussion, likely due to the affected products being end-of-life with no firmware fixes available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CRESTRON | TOUCHSCREEN X70 | >= 3.000.0110.001, < 3.001.0031.001CNA affecteddefault unaffected | |
| CRESTRON | Touchscreen X60s | 3.002.1061CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.