CVE-2025-47415
Severity CVSS v4.0:
MEDIUM
Type:
CWE-22
Path Traversal
Publication date:
09/09/2025
Last modified:
11/09/2025
Description
Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;) vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Confirmed Affected Hardware: TSW-760, TSW-1060 <br />
<br />
<br />
<br />
Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued)<br />
<br />
<br />
<br />
<br />
<br />
For x70 <br />
<br />
<br />
<br />
The Affected Firmware:- 3.000.0110.001 and versions below <br />
<br />
<br />
<br />
The Fixed Firmware:- 3.001.0031.001
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM