← back
CVE-2019-3931

CVE-2019-3931

EPSS 5.9%CWE-88
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vulnerability to upload files to the device and ultimately execute code as root.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →