266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Fixes

Solution

Crestron recommends updating to firmware version 6.4.1.8 or higher. The firmware version will applies user permissions to API requests.


Workaround

Limit all API usage to users with full permissions.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00047}

epss

{'score': 0.00054}


Wed, 07 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Title User Permissions on Network API
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Crestron

Published:

Updated: 2025-05-07T14:03:50.793Z

Reserved: 2025-05-06T19:36:18.441Z

Link: CVE-2025-47420

cve-icon Vulnrichment

Updated: 2025-05-07T13:46:25.389Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-06T22:15:17.180

Modified: 2025-05-07T14:13:20.483

Link: CVE-2025-47420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.