CVE-2019-3929 Details
Description
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Crestron Multiple Products Command Injection Vulnerability | Apr 15, 2022 | May 6, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| crestron am-100 firmware | 1.6.0.2 |
CPE
Remediation
| |
| crestron am-100 | All versions |
CPE
Remediation
| |
| crestron am-101 firmware | 2.7.0.2 |
CPE
Remediation
| |
| crestron am-101 | All versions |
CPE
Remediation
| |
| barco wepresent wipg-1000p firmware | 2.3.0.10 |
CPE
Remediation
| |
| barco wepresent wipg-1000p | All versions |
CPE
Remediation
| |
| barco wepresent wipg-1600w firmware | < 2.4.1.19 |
CPE
Remediation
| |
| barco wepresent wipg-1600w | All versions |
CPE
Remediation
| |
| extron sharelink 200 firmware | 2.0.3.4 |
CPE
Remediation
| |
| extron sharelink 200 | All versions |
CPE
Remediation
| |
| extron sharelink 250 firmware | 2.0.3.4 |
CPE
Remediation
| |
| extron sharelink 250 | All versions |
CPE
Remediation
| |
| teqavit wips710 firmware | 1.1.0.7 |
CPE
Remediation
| |
| teqavit wips710 | All versions |
CPE
Remediation
| |
| sharp pn-l703wa firmware | 1.4.2.3 |
CPE
Remediation
| |
| sharp pn-l703wa | All versions |
CPE
Remediation
| |
| optoma wps-pro firmware | 1.0.0.5 |
CPE
Remediation
| |
| optoma wps-pro | All versions |
CPE
Remediation
| |
| blackbox hd wireless presentation system firmware | 1.0.0.5 |
CPE
Remediation
| |
| blackbox hd wireless presentation system | All versions |
CPE
Remediation
| |
| infocus liteshow3 firmware | 1.0.16 |
CPE
Remediation
| |
| infocus liteshow3 | All versions |
CPE
Remediation
| |
| infocus liteshow4 firmware | 2.0.0.7 |
CPE
Remediation
| |
| infocus liteshow4 | All versions |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 7, 2025 | Modified Analysis | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 16, 2020 | Modified Analysis | [email protected] |
| Jan 14, 2020 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| May 4, 2019 | CVE Modified | [email protected] |
| May 3, 2019 | Initial Analysis | [email protected] |
| May 3, 2019 | CVE Modified | [email protected] |