CVE-2025-47418
Severity CVSS v4.0:
MEDIUM
Type:
CWE-200
Information Leak / Disclosure
Publication date:
06/05/2025
Last modified:
07/05/2025
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse.<br />
<br />
There is no visible indication when the system is recording and recording can be enabled remotely via a network API. <br />
This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM