Infocus manufactures projection and presentation hardware including the IN3128HD and LiteShow product lines, with a compact vulnerability footprint centered on firmware and authentication mechanisms. The observed weakness classes span authentication bypass, web-based input handling including cross-site scripting, OS command injection, and memory-safety issues, reflecting both network-exposed control interfaces and embedded firmware complexity; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infocus over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3929CRITICAL The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh | Apr 30, 2019 | 9.8 | 99 | YES | YES |
CVE-2019-3930CRITICAL The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh | Apr 30, 2019 | 9.8 | 32 | NO | NO |
CVE-2014-8383HIGH The InFocus IN3128HD projector with firmware 0.26 allows remote attackers to bypass authentication via a direct request to main.html. | May 18, 2015 | 10.0 | 25 | NO | NO |
CVE-2017-14972HIGH InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Manager to reach a file. | Oct 9, 2017 | 7.5 | 24 | NO | NO |
CVE-2014-8384HIGH The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configu | May 18, 2015 | 9.4 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infocus.
Media articles that mention a CVE ID that affects a product developed by Infocus — matched by CVE ID, not by vendor name.