CVE-2025-47418: Recording
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse.
There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47418?
The severity of CVE-2025-47418 is considered high due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-47418?
To fix CVE-2025-47418, update Crestron Automate VX to the latest version that addresses this vulnerability.
What impact does CVE-2025-47418 have on users?
CVE-2025-47418 allows unauthorized actors to remotely start recording without user awareness, risking exposure of sensitive information.
Which versions of Crestron Automate VX are affected by CVE-2025-47418?
CVE-2025-47418 affects Crestron Automate VX versions between 5.6.8161.21536 and 6.4.0.49.
Is there a workaround for CVE-2025-47418 before I can update?
As of now, there is no official workaround for CVE-2025-47418; updating to the latest version is recommended.