CVE-2016-5640
CRITICALCrestron AirMedia AM-100 <1.4.0.13 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.
Exploits (2)
Scores
CVSS v3
9.8
EPSS
0.5233
EPSS Percentile
97.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (1)
crestron/airmedia_am-100_firmware
< 1.2.1
Published
Aug 03, 2016
Tracked Since
Feb 18, 2026