CVE-2016-5640
CRITICALCrestron AirMedia AM-100 <1.4.0.13 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2016-5640. PoCs published by vpnguy-zz, xfox64x.
AI-analyzed exploit summary The repository contains a Python script (`crestcrack.py`) designed to exploit CVE-2016-5640, a vulnerability in certain VPN implementations. The exploit likely involves crafted network requests to achieve unauthorized access or command execution.
Description
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.
Exploits (2)
The repository contains a Python script (`crestcrack.py`) designed to exploit CVE-2016-5640, a vulnerability in certain VPN implementations. The exploit likely involves crafted network requests to achieve unauthorized access or command execution.
This repository contains a functional Metasploit module for exploiting CVE-2016-5640, a remote command injection vulnerability in Crestron AirMedia AM-100 devices. The exploit targets the wireless diagnostics page and executes commands as root via crafted HTTP POST requests.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H