There is no visible indication when the system is recording and recording can be enabled remotely via a network API.
This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13641 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. |
Solution
Crestron recommends updating to firmware version 6.4.1.8 or higher. The firmware version will adds a visual indication on the program video output when recording is started.
Workaround
Inform users in the room that they may be recorded. Also, configure the network to only allow needed systems and/or devices to access the API.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Title | Recording | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Crestron
Published:
Updated: 2025-05-07T14:04:11.178Z
Reserved: 2025-05-06T19:36:18.441Z
Link: CVE-2025-47418
Updated: 2025-05-07T13:46:15.860Z
Status : Awaiting Analysis
Published: 2025-05-06T21:16:20.737
Modified: 2025-05-07T14:13:20.483
Link: CVE-2025-47418
No data.
OpenCVE Enrichment
No data.
EUVD