CVE-2025-47418

MEDIUM

Crestron Automate VX <6.4.0.49 - Info Disclosure

Title source: llm
STIX 2.1

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.

Scores

CVSS v4 5.3
EPSS 0.0034
EPSS Percentile 25.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
Crestron/Automate VX 5.6.8161.21536 - 6.4.0.49
Published May 06, 2025
Tracked Since Feb 18, 2026