CVE-2016-5640

CRITICAL

Crestron AirMedia AM-100 <1.4.0.13 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.

Exploits (2)

nomisec WORKING POC 7 stars
by vpnguy-zz · poc
https://github.com/vpnguy-zz/CrestCrack
nomisec WORKING POC 2 stars
by xfox64x · poc
https://github.com/xfox64x/CVE-2016-5640

Scores

CVSS v3 9.8
EPSS 0.5233
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
crestron/airmedia_am-100_firmware < 1.2.1
Published Aug 03, 2016
Tracked Since Feb 18, 2026