CVE-2018-11229: OS Command Injection
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-11229.
What is the severity of CVE-2018-11229?
The severity of CVE-2018-11229 is critical, with a severity value of 9.8.
How does CVE-2018-11229 allow remote code execution?
CVE-2018-11229 allows unauthenticated remote code execution through command injection in the Crestron Toolbox Protocol (CTP).
Which devices are affected by CVE-2018-11229?
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before version 2.001.0037.001 are affected by CVE-2018-11229.
How can I fix the CVE-2018-11229 vulnerability?
To fix the CVE-2018-11229 vulnerability, update your Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices to version 2.001.0037.001 or later.