Web1 vuln-feed

Finding #105

Inventory item apache-test 2.4.37 (software, apache)
TitleCrestron Multiple Products: Crestron Multiple Products Command Injection Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:12Z
Last updated2026-06-11T07:35:12Z
Source advisoryCrestron Multiple Products: Crestron Multiple Products Command Injection Vulnerability
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

Update status