CVE-2018-11228: Code Injection
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Crestron vulnerability?
The vulnerability ID for this Crestron vulnerability is CVE-2018-11228.
What is the severity of CVE-2018-11228?
CVE-2018-11228 has a severity rating of 9.8 (Critical).
Which devices are affected by CVE-2018-11228?
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before version 2.001.0037.001 are affected by CVE-2018-11228.
How can an attacker exploit CVE-2018-11228?
An attacker can exploit CVE-2018-11228 by performing unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP).
Is there a patch available for CVE-2018-11228?
Yes, a patch is available for CVE-2018-11228. It is recommended to update affected devices to version 2.001.0037.001 or later.