CVE-2025-47420
HIGHCrestron Automate VX <6.4.0.49 - Privilege Escalation
Title source: llmDescription
266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
References (3)
Core 3
Core References
Various Sources vendor-advisory
https://security.crestron.com/
Various Sources patch
https://www.crestron.com/Software-Firmware/Software/Automate-VX-Software/6-4-1-8
Various Sources release-notes
https://www.crestron.com/release_notes/automate_vx_6.4.1.8_release_notes.pdf
Scores
CVSS v4
8.7
EPSS
0.0031
EPSS Percentile
22.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (1)
Crestron/Automate VX
5.6.8161.21536 - 6.4.0.49
Published
May 06, 2025
Tracked Since
Feb 18, 2026