Crestron Automate VX Exposure of Sensitive Information Vulnerability Allowing Functionality Misuse
Vulnerability
A vulnerability in Crestron Automate VX, versions 5.6.8161.21536 through 6.4.0.49, allows for the unauthorized exposure of sensitive information and misuse of functionality. The issue arises because there is no visible indication when the system is recording, and recording can be enabled remotely via a network API.
Impact
Exploitation of this vulnerability could lead to unauthorized recording without the knowledge of the user or administrator.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
5.2remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
