Back

CRITICAL

Crestron DGE-100 Console Command Injection (FIXED)

Published Jul 10, 2018

Description

The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.

Affected products

Remediation

Vendor solution

Users should update affected devices to the latest firmware version (1.3384.00059.001 or higher) available from Crestron's product pages.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Jul 10, 2018
Updated Sep 16, 2024
Reserved Jan 12, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a