Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Crestron Electronics, Inc.

First CVE: Aug 3, 2016Active for: 10 yearsTotal CVEs: 40
70.5
VTI Score
TOP TARGET

Crestron Electronics develops control and automation systems for enterprise facilities, conference rooms, and integrated audiovisual environments, with vulnerability exposure concentrating in its AM series media and amplification devices and their firmware. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the firmware's role in networked devices that often sit behind minimal authentication boundaries. The recurring weakness classes—improper access control, OS command injection, and authentication flaws—are characteristic of embedded control software where trust assumptions and input handling directly translate to facility compromise or lateral-network movement. Defenders should treat patches for this vendor's control-plane devices as high-priority and audit network segmentation around deployed instances. Live exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
2.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Crestron Electronics, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2016
9 years ago
Most Recent CVE
Jan 23, 2024
913 days ago

Self-Reporting Analysis

Of all the CVEs published by Crestron Electronics, Inc. as a CNA, 0.0% affect products that Crestron Electronics, Inc. develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 8 (100.0%)

Of all the CVEs published that affect products developed by Crestron Electronics, Inc., 0.0% are self-published by Crestron Electronics, Inc. as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 40 (100.0%)

Products(58 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-3929CRITICAL
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh
Apr 30, 20199.899YESYES
CVE-2022-23178CRITICAL
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are d
Jan 15, 20229.886NOYES
CVE-2017-16709HIGH
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via u
Jul 11, 20187.280NOYES
CVE-2019-3932CRITICAL
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated
Apr 30, 20199.849NONO
CVE-2016-5639HIGH
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a .. (d
Aug 3, 20167.538NOYES
CVE-2018-10630CRITICAL
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to us
Aug 10, 20189.835NONO
CVE-2019-3910CRITICAL
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to acces
Jan 18, 20199.134NONO
CVE-2016-5668CRITICAL
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call.
Aug 3, 20169.833NONO
CVE-2019-18184CRITICAL
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
Nov 27, 20199.832NONO
CVE-2019-3930CRITICAL
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh
Apr 30, 20199.832NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
10%
38%
53%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (10.0%)
Network36 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None37 (92.5%)
Unknown0 (0.0%)
Required3 (7.5%)
Privileges Required
Low8 (20.0%)
High2 (5.0%)
None30 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
1 CVE
2.5% of CVEs· 99th percentile
Metasploit
2 CVEs
5.0% of CVEs· 98th percentile
Nuclei
2 CVEs
5.0% of CVEs· 96th percentile
ExploitDB
4 CVEs
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Crestron Electronics, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Crestron Electronics, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Crestron Electronics, Inc.'s Products

View all 5 CNAs →

Top CWEs