CVE-2026-7865

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
05/05/2026
Last modified:
05/05/2026

Description

A hidden console command is vulnerable to command injection<br /> flaw when control characters are passed to its second argument. <br /> <br /> A third party researcher Eugene Lim had discovered vulnerability<br /> in the way console command passes to a popen function call. Attackers with<br /> authenticated access to SSH console of Crestron devices may use to run<br /> underlying OS commands.