vciy

CVEs we hold for Crestron

Records whose assigning authority named Crestron as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-7865Hidden Console CommandCrestron Electronics Touchpanels (x60/x70)
CVE-2025-47421Privilege escalation via SCP loginCRESTRON TOUCHSCREENS x70
CVE-2025-47420User Permissions on Network APICrestron Automate VX
CVE-2025-47419Non-Secure AccessCrestron Automate VX
CVE-2025-47418RecordingCrestron Automate VX
CVE-2025-47417Enable Debug ImagesCrestron Automate VX
CVE-2025-47416ConsoleFindCommandMatchListCRESTRON Touchscreen x60s
CVE-2025-47415RECWAVE Filepath TraversalCRESTRON TOUCHSCREENS x60, x70 series
CVE-2023-6926Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Crestron AM-300Crestron AM-300
CVE-2019-3939no title heldCrestron AirMedia
CVE-2019-3938no title heldCrestron AirMedia
CVE-2019-3937no title heldCrestron AirMedia
CVE-2019-3936no title heldCrestron AirMedia
CVE-2019-3935no title heldCrestron AirMedia
CVE-2019-3934no title heldCrestron AirMedia
CVE-2019-3933no title heldCrestron AirMedia
CVE-2019-3932no title heldCrestron AirMedia
CVE-2019-3931no title heldCrestron AirMedia
CVE-2019-3930no title heldCrestron AirMedia, Barco WePresent, Extron ShareLink, Teq…
CVE-2019-3929no title heldCrestron AirMedia, Barco WePresent, Extron ShareLink, Teq…
CVE-2019-3928no title heldCrestron AirMedia
CVE-2019-3927no title heldCrestron AirMedia
CVE-2019-3926no title heldCrestron AirMedia
CVE-2019-3925no title heldCrestron AirMedia
CVE-2019-3910no title heldn/a Crestron AM-100 Before 1.6.0.2
CVE-2018-5553Crestron DGE-100 Console Command Injection (FIXED)Crestron DM-DGE-200-C

26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.