flaw when control characters are passed to its second argument.
A third party researcher Eugene Lim had discovered vulnerability
in the way console command passes to a popen function call. Attackers with
authenticated access to SSH console of Crestron devices may use to run
underlying OS commands.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 06 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crestron
Crestron touchpanels X60 Crestron touchpanels X70 |
|
| Vendors & Products |
Crestron
Crestron touchpanels X60 Crestron touchpanels X70 |
Tue, 05 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A third party researcher Eugene Lim had discovered vulnerability in the way console command passes to a popen function call. Attackers with authenticated access to SSH console of Crestron devices may use to run underlying OS commands. | |
| Title | Hidden Console Command | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Crestron
Published:
Updated: 2026-05-06T15:25:23.058Z
Reserved: 2026-05-05T13:36:54.938Z
Link: CVE-2026-7865
Updated: 2026-05-05T18:31:40.724Z
Status : Awaiting Analysis
Published: 2026-05-05T16:16:19.730
Modified: 2026-05-07T14:53:48.473
Link: CVE-2026-7865
No data.
OpenCVE Enrichment
Updated: 2026-05-06T09:21:36Z