CVE-2026-7865
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
05/05/2026
Última modificación:
05/05/2026
Descripción
*** Pendiente de traducción *** A hidden console command is vulnerable to command injection<br />
flaw when control characters are passed to its second argument. <br />
<br />
A third party researcher Eugene Lim had discovered vulnerability<br />
in the way console command passes to a popen function call. Attackers with<br />
authenticated access to SSH console of Crestron devices may use to run<br />
underlying OS commands.
Impacto
Puntuación base 4.0
7.40
Gravedad 4.0
ALTA



