CVE-2025-47419: Non-Secure Access
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.
The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords.
This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47419?
The severity of CVE-2025-47419 is high due to the exposure of sensitive information such as user passwords through cleartext transmissions.
How do I fix CVE-2025-47419?
To fix CVE-2025-47419, update Crestron Automate VX to version 6.4.1.8 or later to enable secure communication.
What type of data is affected by CVE-2025-47419?
CVE-2025-47419 affects sensitive data, including user passwords, transmitted over non-secure channels.
Which versions of Automate VX are impacted by CVE-2025-47419?
CVE-2025-47419 impacts Crestron Automate VX versions between 5.6.8161.21536 and 6.4.0.49.
Is there a workaround for CVE-2025-47419 while waiting for an update?
A temporary workaround for CVE-2025-47419 includes disabling access over non-secure network ports until the software is updated.