PT-2018-10411 · Crestron+1 · Crestron Tsw-1060+5

Published

2018-06-08

·

Updated

2019-05-02

·

CVE-2018-11228

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices versions prior to 2.001.0037.001
Description The issue allows unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP). This is due to command injection vulnerabilities in various CTP Console commands, including RESTARTSERVICE, ROUTEDELETE, MAKEDIR, FGETFILE, REMOVEDIR, UPDATEPASSWORD, WIFIWEPPASSWORD, DIR, FPUTFILE, DELETE, CD, WIFISSID, WIFIPSKPASSWORD, ISDIR, ROUTEADD, UDIR, ADDUSER, MOVEFILE, COPYFILE, EDIDMUX, and WIFIWEPHEXPASSWORD.
Recommendations For Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices versions prior to 2.001.0037.001, update to version 2.001.0037.001 or later to resolve the issue. As a temporary workaround, consider disabling the Bash shell service in Crestron Toolbox Protocol (CTP) until a patch is available. Restrict access to the CTP Console commands to minimize the risk of exploitation. Avoid using the vulnerable CTP Console commands until the issue is resolved.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11228
ZDI-18-1080
ZDI-18-915
ZDI-18-916
ZDI-18-917
ZDI-18-918
ZDI-18-919
ZDI-18-921
ZDI-18-922
ZDI-18-923
ZDI-18-924
ZDI-18-925
ZDI-18-926
ZDI-18-927
ZDI-18-928
ZDI-18-929
ZDI-18-931
ZDI-18-933
ZDI-18-934
ZDI-18-935
ZDI-18-937
ZDI-18-938

Affected Products

Bash
Crestron Tsw-1060
Crestron Tsw-560
Crestron Tsw-560-Nc
Crestron Tsw-760
Crestron Tsw-760-Nc