CVE-2019-3929
Crestron Multiple Products Command Injection Vulnerability
⚠ KEVEPSS 99.0%
Description
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
How to fix CVE-2019-3929
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2019-3929 being exploited?
Yes — CVE-2019-3929 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.