CVE-2025-47420: User Permissions on Network API
Published May 6, 2025
·Updated
266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Affected Software
1 affected component
Crestron Automate VX>=5.6.8161.21536<=6.4.0.49
Remediation
Information
Crestron recommends updating to firmware version 6.4.1.8 or higher. The firmware version will applies user permissions to API requests.
Event History
May 6, 2025
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Feb 10, 57332
Event
via FIRST·12:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-47420?
CVE-2025-47420 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2025-47420?
To fix CVE-2025-47420, you should update Crestron Automate VX to version 6.4.1.8 or later.
3
Which versions of Crestron Automate VX are affected by CVE-2025-47420?
CVE-2025-47420 affects versions of Crestron Automate VX from 5.6.8161.21536 through 6.4.0.49.
4
What type of vulnerability is CVE-2025-47420?
CVE-2025-47420 is a privilege escalation vulnerability.
5
What product does CVE-2025-47420 impact?
CVE-2025-47420 impacts the Crestron Automate VX product.