A hidden console command is vulnerable to command injection
flaw when control characters are passed to its second argument.
A third party researcher Eugene Lim had discovered vulnerability
in the way console command passes to a popen function call. Attackers with
authenticated access to SSH console of Crestron devices may use to run
underlying OS commands.
CVSS
No CVSS.
References
Configurations
No configuration.
History
05 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 16:16
Updated : 2026-05-07 14:53
NVD link : CVE-2026-7865
Mitre link : CVE-2026-7865
CVE.ORG link : CVE-2026-7865
JSON object : View
Products Affected
No product.
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
