CVE-2016-5640

CRITICAL

Crestron AirMedia AM-100 <1.4.0.13 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2016-5640. PoCs published by vpnguy-zz, xfox64x.

AI-analyzed exploit summary The repository contains a Python script (`crestcrack.py`) designed to exploit CVE-2016-5640, a vulnerability in certain VPN implementations. The exploit likely involves crafted network requests to achieve unauthorized access or command execution.

Description

Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.

Exploits (2)

nomisec WORKING POC 7 stars
by vpnguy-zz · poc
https://github.com/vpnguy-zz/CrestCrack

The repository contains a Python script (`crestcrack.py`) designed to exploit CVE-2016-5640, a vulnerability in certain VPN implementations. The exploit likely involves crafted network requests to achieve unauthorized access or command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Unknown VPN software (likely Crestron or similar)
No auth needed
Prerequisites: Network access to vulnerable VPN endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 2 stars
by xfox64x · poc
https://github.com/xfox64x/CVE-2016-5640

This repository contains a functional Metasploit module for exploiting CVE-2016-5640, a remote command injection vulnerability in Crestron AirMedia AM-100 devices. The exploit targets the wireless diagnostics page and executes commands as root via crafted HTTP POST requests.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Crestron AirMedia AM-100 (firmware <1.4.0.13)
No auth needed
Prerequisites: Network access to the target device · SSL/TLS enabled on port 443
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92216
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/603047

Scores

CVSS v3 9.8
EPSS 0.5233
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
crestron/airmedia_am-100_firmware < 1.2.1
Published Aug 03, 2016
Tracked Since Feb 18, 2026