Crestron Electronics develops control and automation systems for enterprise facilities, conference rooms, and integrated audiovisual environments, with vulnerability exposure concentrating in its AM series media and amplification devices and their firmware. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the firmware's role in networked devices that often sit behind minimal authentication boundaries. The recurring weakness classes—improper access control, OS command injection, and authentication flaws—are characteristic of embedded control software where trust assumptions and input handling directly translate to facility compromise or lateral-network movement. Defenders should treat patches for this vendor's control-plane devices as high-priority and audit network segmentation around deployed instances. Live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crestron Electronics, Inc. over time
Of all the CVEs published by Crestron Electronics, Inc. as a CNA, 0.0% affect products that Crestron Electronics, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Crestron Electronics, Inc., 0.0% are self-published by Crestron Electronics, Inc. as a CNA.
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3929CRITICAL The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh | Apr 30, 2019 | 9.8 | 99 | YES | YES |
CVE-2022-23178CRITICAL An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are d | Jan 15, 2022 | 9.8 | 86 | NO | YES |
CVE-2017-16709HIGH Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via u | Jul 11, 2018 | 7.2 | 80 | NO | YES |
CVE-2019-3932CRITICAL Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated | Apr 30, 2019 | 9.8 | 49 | NO | NO |
CVE-2016-5639HIGH Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a .. (d | Aug 3, 2016 | 7.5 | 38 | NO | YES |
CVE-2018-10630CRITICAL For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to us | Aug 10, 2018 | 9.8 | 35 | NO | NO |
CVE-2019-3910CRITICAL Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to acces | Jan 18, 2019 | 9.1 | 34 | NO | NO |
CVE-2016-5668CRITICAL Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call. | Aug 3, 2016 | 9.8 | 33 | NO | NO |
CVE-2019-18184CRITICAL Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. | Nov 27, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-3930CRITICAL The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh | Apr 30, 2019 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crestron Electronics, Inc..
Media articles that mention a CVE ID that affects a product developed by Crestron Electronics, Inc. — matched by CVE ID, not by vendor name.