Skip to content
COOEY

FAIL › dossier

Crestron

VENDOR

· dossier confidence 80%

Crestron Electronics is a private American multinational corporation providing intelligent control solutions across multiple sectors. Its security posture is compromised by a history of critical and high-severity remote code execution vulnerabilities in its products, requiring strict patch management and secure-by-design protocols.

PROFILE
CategoryvendorWhat they doCrestron Electronics is an American multinational corporation that provides intelligent control solutions for enterprise, education, government, and residential use cases.HQMeridian, Idaho, United StatesSize1001-5000Ownershipprivate Websitehttps://www.crestron.com ↗
SECURITY POSTURE

The company has a documented history of critical and high-severity remote code execution vulnerabilities in its products, indicating a need for rigorous patch management and secure-by-design practices.

Notable failures
  • CVE-2019-3929: Remote unauthenticated RCE via command injection on file_transfer.cgi
  • CVE-2019-18184: Remote command execution as root on DMC-STRO 1.0 devices
Patterns: repeated unpatched edge-device RCEs
Reputationsevere-fallout (-0.39) · 7 trusted sources CoverageCISA · app.opencve.io · cooey · cvedb.shodan.io · recentbreaches.com · www.cvefind.com
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-04-15 CVE-2019-3929 high Crestron products allow remote, unauthenticated attackers to execute OS commands as root via command injection on the file_transfer.cgi endpoint.
2019-11-27 CVE-2019-18184 critical CVE-2019-18184: Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell m
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
Widespread condemnation and recognition of exploitation.
cooey ↗severe-fallout-0.70
Neutral reporting of the vulnerability.
"Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function."
www.cvefind.com ↗severe-fallout+0.00
Neutral listing of the CVE.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
cvedb.shodan.io ↗severe-fallout+0.00
Neutral listing of the CVE.
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
app.opencve.io ↗severe-fallout+0.00
Neutral listing of the CVE.
"CVE 2026-47362 2026-08-08 4.6 Medium"
CISA ↗severe-fallout-0.60
Recognition of exploitation, indicating severity.
"CISA Adds One Known Exploited Vulnerability to Catalog"
recentbreaches.com ↗severe-fallout-0.50
Implies widespread exposure and potential compromise.
"31082 breaches tracked"
www.hipaajournal.com ↗severe-fallout-0.90
No relevant content.
Open questions: Current patch management processes for legacy Crestron devices · Specific remediation steps taken for CVE-2019-3929 and CVE-2019-18184
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-29 04:05:12.139540+00:00