CVE 5.9 MEDIUM

ConsoleFindCommandMatchList_CVE-2025-47416

5.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList.



A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the /dev/shm/symproc/c directory in alphabetical order to identify console commands. Permission levels are inferred from the integer values present in each command's file name. 



Confirmed Affected Hardware: TSW-760, TSW-1060



Confirmed Affected Firmware: 3.002.1061 



Fixed Firmware: no fixed released (product is discontinued and end of life)



 



For x70  



The Affected Firmware:- 3.000.0110.001  and versions below



The Fixed Firmware:- 3.001.0031.001

Basic Information

ID CVE-2025-47416
Source Crestron
Published Sep 9, 2025 at 13:52
Modified Sep 9, 2025 at 14:06

Affected Product

Vendor CRESTRON
Product TOUCHSCREEN x70
Version 3.000.0110.001
Affected Versions CRESTRON TOUCHSCREEN x70 3.000.0110.001
CRESTRON Touchscreen x60s 3.002.1061

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.