peter bassill · operator
$ cve CVE-2016-5666 JSON

CVE-2016-5666

9.8
CRITICAL · CVSS 3.0 · EPSS 4.2% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote attackers to obtain access by setting the value of objresp.authenabled to 1.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.2% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploitnone known
Published2016-08-03
Last modified2026-06-17

Affected (2)

VendorProduct
crestrondm-txrx-100-str
crestrondm-txrx-100-str firmware

References

→ the Explorer  ·  watch your stack  ·  NVD