c
crestron
Security Risk Profile
41
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 47 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 3, 2016 to present
47
Total CVEs
40
Critical+High
1
Exploited
36
Unpatched
Threat Assessment
Avg CVSS
8.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
36
Critical/High
Risk Level
41/100
medium
⚠️ 1 Active Exploits
Severity Distribution
Critical
23High
17Medium
7Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
5Age Distribution
Common Weaknesses (CWE)
1
Command Injection
8
2
OS Command Injection
7
3
XSS
4
4
Path Traversal
2
5
Infoleak
2
Most Affected Products
1. Crestron AM-100 firmware30
2. Crestron AM-101 firmware30
3. Crestron Airmedia Am-100 Firmware6
4. Crestron Dm-txrx-100-str Firmware6
5. Crestron Automate VX4
Recent Vulnerabilities
See more →CVE-2026-7865
CVSS 7.4EPSS 0%high
Hidden Console Command
5/5/2026🔧 No Patch
CVE-2025-47415
CVSS 6.8medium
RECWAVE Filepath Traversal
9/9/2025🔧 No Patch
CVE-2025-47421
CVSS 8.6high
Privilege escalation via SCP login
9/3/2025🔧 No Patch
CVE-2025-47420
CVSS 8.7EPSS 0%high
User Permissions on Network API
5/6/2025
CVE-2025-47419
CVSS 10.0EPSS 0%critical
Non-Secure Access
5/6/2025
CVE-2025-47418
CVSS 5.3EPSS 0%medium
Recording
5/6/2025
CVE-2025-47417
CVSS 5.1EPSS 0%medium
Enable Debug Images
5/6/2025
CVE-2023-6926
CVSS 8.4high
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Crestron AM-300
1/23/2024
CVE-2023-38405
CVSS 7.5high
7/17/2023🔧 No Patch
CVE-2022-40298
CVSS 8.8high
9/22/2022🔧 No Patch
Monitor crestron in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.