CVE-2025-47421: Privilege escalation via SCP login
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001.
A specially crafted SCP command sent via SSH login string can lead a valid administrator user to gain Privileged Operating System access on the device.
Following Products Models are affected:
TSW-x70 TSW-x60 TST-1080 AM-3000/3100/3200 Soundbar VB70 HD-PS622/621/402 HD-TXU-RXU-4kZ-211 HD-MDNXM-4KZ-E
Note: additional firmware updates will be published once made available
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47421?
CVE-2025-47421 has been assessed as a high severity vulnerability due to its potential for argument injection through crafted SCP commands.
How do I fix CVE-2025-47421?
To fix CVE-2025-47421, you should upgrade the affected Crestron TOUCHSCREENS x70 firmware to version 3.002.0040.001 or later.
Which devices are affected by CVE-2025-47421?
CVE-2025-47421 affects Crestron TOUCHSCREENS x70 models running firmware versions from 3.001.0031.001 to 3.001.0034.001.
What type of vulnerability is CVE-2025-47421?
CVE-2025-47421 is categorized as an argument injection vulnerability due to improper neutralization of argument delimiters.
When was CVE-2025-47421 discovered?
The details regarding the discovery date of CVE-2025-47421 are not explicitly provided in the current documentation.