No analysis available yet.
Vendor Solution
Crestron recommends updating to firmware version 6.4.1.8 or higher. The firmware version will applies user permissions to API requests.
Vendor Workaround
Limit all API usage to users with full permissions.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13651 | 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Title | User Permissions on Network API | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Crestron
Published:
Updated: 2025-05-07T14:03:50.793Z
Reserved: 2025-05-06T19:36:18.441Z
Link: CVE-2025-47420
Updated: 2025-05-07T13:46:25.389Z
Status : Deferred
Published: 2025-05-06T22:15:17.180
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-47420
No data.
OpenCVE Enrichment
No data.
EUVD