← Back to CVE List
Vulnerability Intelligence Report
Crestron Multiple Products Command Injection Vulnerability

CVE-2019-3929

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:98.95%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-79 ↗CWE-79 OS Command Injection

Affected Products & Versions

Vendor Product Affected Versions
Crestron Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4. Crestron AM-100 firmware 1.6.0.2 (affected), Crestron AM-101 firmware 2.7.0.1 (affected), Barco wePresent WiPG-1000P firmware 2.3.0.10 (affected), Barco wePresent WiPG-1600W before firmware 2.4.1.19 (affected), Extron ShareLink 200/250 firmware 2.0.3.4 (affected), Teq AV IT WIPS710 firmware 1.1.0.7 (affected), SHARP PN-L703WA firmware 1.4.2.3 (affected), Optoma WPS-Pro firmware 1.0.0.5 (affected), Blackbox HD WPS firmware 1.0.0.5 (affected), InFocus LiteShow3 firmware 1.0.16 (affected), and InFocus LiteShow4 2.0.0.7 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
98.952%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTenable Network Security, Inc. · Vendor · USA
Reserved2019-01-03T00:00:00
Published2019-04-30T20:21:09
Last Updated2025-10-21T23:45:38

LINK COPIED TO CLIPBOARD