EXPOSURES › CVE-2019-3929
CVE-2019-3929
HIGH ⌖ ON CISA KEV · EXPLOITEDCrestron products allow remote, unauthenticated attackers to execute OS commands as root via command injection on the file_transfer.cgi endpoint.
A remote, unauthenticated attacker can exploit this command injection flaw to run arbitrary OS commands with root privileges, enabling full system compromise and lateral movement. For DIB organizations, this represents a critical RCE vulnerability that bypasses authentication controls and violates CMMC/NIST 800-171 requirements for protecting systems and information. Organizations must immediately patch Crestron products and restrict network access to unpatched systems.
Shame score — A remote, unauthenticated command injection flaw allowing root-level OS command execution is a severe, avoidable vulnerability that was actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.