flaw when control characters are passed to its second argument.
A third party researcher Eugene Lim had discovered vulnerability
in the way console command passes to a popen function call. Attackers with
authenticated access to SSH console of Crestron devices may use to run
underlying OS commands.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 06 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crestron
Crestron touchpanels X60 Crestron touchpanels X70 |
|
| Vendors & Products |
Crestron
Crestron touchpanels X60 Crestron touchpanels X70 |
Tue, 05 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A third party researcher Eugene Lim had discovered vulnerability in the way console command passes to a popen function call. Attackers with authenticated access to SSH console of Crestron devices may use to run underlying OS commands. | |
| Title | Hidden Console Command | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Crestron
Published:
Updated: 2026-05-06T15:25:23.058Z
Reserved: 2026-05-05T13:36:54.938Z
Link: CVE-2026-7865
Updated: 2026-05-05T18:31:40.724Z
Status : Awaiting Analysis
Published: 2026-05-05T16:16:19.730
Modified: 2026-05-07T14:53:48.473
Link: CVE-2026-7865
No data.
OpenCVE Enrichment
Updated: 2026-05-06T09:21:36Z