CVE-2025-47415
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
09/09/2025
Última modificación:
11/09/2025
Descripción
*** Pendiente de traducción *** Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;) vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Confirmed Affected Hardware: TSW-760, TSW-1060 <br />
<br />
<br />
<br />
Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued)<br />
<br />
<br />
<br />
<br />
<br />
For x70 <br />
<br />
<br />
<br />
The Affected Firmware:- 3.000.0110.001 and versions below <br />
<br />
<br />
<br />
The Fixed Firmware:- 3.001.0031.001
Impacto
Puntuación base 4.0
6.80
Gravedad 4.0
MEDIA