Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Barco

First CVE: Jan 12, 2017Active for: 10 yearsTotal CVEs: 40
59.2
VTI Score
TOP TARGET

Barco manufactures a focused portfolio of enterprise presentation and collaboration devices, notably its ClickShare wireless presentation systems and Control Room Management Suite, which serve conference rooms and control centers across corporate and critical-infrastructure environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in input-handling and credential-management weaknesses, including cross-site scripting, command injection, OS command injection, hard-coded credentials, and sensitive-information exposure that are characteristic of embedded web interfaces and management applications. The recurrence of these weakness classes across the ClickShare and Control Room product lines reflects the intersection of complex network protocols, administrative access, and often-networked deployment in high-value environments. Defenders should prioritize inventory and patching of Barco devices, particularly those exposed to untrusted networks or facing internet connectivity; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
2.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Barco over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 12, 2017
9 years ago
Most Recent CVE
Jun 2, 2022
1,513 days ago

Products(26 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-3929CRITICAL
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh
Apr 30, 20199.899YESYES
CVE-2022-26233HIGH
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components
Apr 3, 20227.543NOYES
CVE-2016-3149CRITICAL
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vector
Jan 12, 20179.833NONO
CVE-2019-18830CRITICAL
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Butto
Dec 16, 20199.832NONO
CVE-2019-3930CRITICAL
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh
Apr 30, 20199.832NONO
CVE-2016-3152CRITICAL
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.
Jan 12, 20179.832NONO
CVE-2020-28333CRITICAL
Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking
Nov 24, 20209.831NONO
CVE-2020-28329CRITICAL
Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password t
Nov 24, 20209.829NONO
CVE-2020-28334CRITICAL
Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has
Nov 24, 20209.829NONO
CVE-2019-18826CRITICAL
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the function
Dec 16, 20199.828NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
38%
35%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (7.5%)
Network35 (87.5%)
Unknown0 (0.0%)
Physical2 (5.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (90.0%)
High4 (10.0%)
Unknown0 (0.0%)
User Interaction
None31 (77.5%)
Unknown0 (0.0%)
Required9 (22.5%)
Privileges Required
Low7 (17.5%)
High3 (7.5%)
None30 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
1 CVE
2.5% of CVEs· 99th percentile
Metasploit
1 CVE
2.5% of CVEs· 97th percentile
Nuclei
2 CVEs
5.0% of CVEs· 96th percentile
ExploitDB
1 CVE
2.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Barco.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Barco — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Barco's Products

View all 2 CNAs →

Top CWEs