Description
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
References (3)
Core 3
Core References
Various Sources vendor-advisory
https://security.crestron.com/
Various Sources patch
https://www.crestron.com/Software-Firmware/Software/Automate-VX-Software/6-4-1-8
Various Sources release-notes
https://www.crestron.com/release_notes/automate_vx_6.4.1.8_release_notes.pdf
Scores
CVSS v4
10.0
EPSS
0.0024
EPSS Percentile
14.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-319
Status
published
Products (1)
Crestron/Automate VX
5.6.8161.21536 - 6.4.0.49
Published
May 06, 2025
Tracked Since
Feb 18, 2026