Home

Description

266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.

PUBLISHED Reserved 2025-05-06 | Published 2025-05-06 | Updated 2025-05-07 | Assigner Crestron




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

5.6.8161.21536 (custom)
affected

Credits

Crestron Electronics Inc finder

References

security.crestron.com/ vendor-advisory

www.crestron.com/...re/Software/Automate-VX-Software/6-4-1-8 patch

www.crestron.com/...es/automate_vx_6.4.1.8_release_notes.pdf release-notes

cve.org (CVE-2025-47420)

nvd.nist.gov (CVE-2025-47420)

Download JSON