Security Advisory

CVE-2026-7865

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-05-05 15:05:12
Last updated 2026-05-06 15:25:23
Assigner Crestron
State PUBLISHED

Description

A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument.  A third party researcher Eugene Lim had discovered vulnerability in the way console command passes to a popen function call. Attackers with authenticated access to SSH console of Crestron devices may use to run underlying OS commands.