Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001.
A specially crafted SCP command sent via SSH login string can lead a valid administrator user to gain Privileged Operating System access on the device.
Following Products Models are affected:
TSW-x70
TSW-x60
TST-1080
AM-3000/3100/3200
Soundbar VB70
HD-PS622/621/402
HD-TXU-RXU-4kZ-211
HD-MDNXM-4KZ-E
*Note: additional firmware updates will be published once made available
A specially crafted SCP command sent via SSH login string can lead a valid administrator user to gain Privileged Operating System access on the device.
Following Products Models are affected:
TSW-x70
TSW-x60
TST-1080
AM-3000/3100/3200
Soundbar VB70
HD-PS622/621/402
HD-TXU-RXU-4kZ-211
HD-MDNXM-4KZ-E
*Note: additional firmware updates will be published once made available
Metrics
Affected Vendors & Products
References
History
Wed, 03 Sep 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Crestron
Crestron touchscreens X70 |
|
Vendors & Products |
Crestron
Crestron touchscreens X70 |
Wed, 03 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 03 Sep 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid administrator user to gain Privileged Operating System access on the device. Following Products Models are affected: TSW-x70 TSW-x60 TST-1080 AM-3000/3100/3200 Soundbar VB70 HD-PS622/621/402 HD-TXU-RXU-4kZ-211 HD-MDNXM-4KZ-E *Note: additional firmware updates will be published once made available | |
Title | Privilege escalation via SCP login | |
Weaknesses | CWE-88 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Crestron
Published:
Updated: 2025-09-03T13:59:32.186Z
Reserved: 2025-05-06T19:36:18.441Z
Link: CVE-2025-47421

Updated: 2025-09-03T13:59:21.199Z

Status : Received
Published: 2025-09-03T14:15:45.607
Modified: 2025-09-03T14:15:45.607
Link: CVE-2025-47421

No data.

Updated: 2025-09-03T20:26:52Z