CVE-2025-47415: RECWAVE Filepath Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001.
Confirmed Affected Hardware: TSW-760, TSW-1060
Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued)
For x70
The Affected Firmware:- 3.000.0110.001 and versions below
The Fixed Firmware:- 3.001.0031.001
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47415?
CVE-2025-47415 has been classified with a medium severity rating due to its potential for unauthorized access through path traversal.
How do I fix CVE-2025-47415?
To fix CVE-2025-47415, update the firmware of the Crestron Touchscreens x70 to a version above 3.001.0031.001.
Which Crestron Touchscreen models are affected by CVE-2025-47415?
The affected models include TSW-760 and other Crestron Touchscreens x70 running vulnerable firmware versions.
What is the impact of CVE-2025-47415?
The impact of CVE-2025-47415 includes the potential for an attacker to execute unauthorized commands by manipulating file paths.
When was CVE-2025-47415 disclosed?
CVE-2025-47415 was disclosed as part of a routine security update for Crestron Touchscreens.