CVE-2025-47416 Details
Description
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList. A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the /dev/shm/symproc/c directory in alphabetical order to identify console commands. Permission levels are inferred from the integer values present in each command's file name. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061 Fixed Firmware: no fixed released (product is discontinued and end of life) For x70 The Affected Firmware:- 3.000.0110.001 and versions below The Fixed Firmware:- 3.001.0031.001
A vulnerability in the ConsoleFindCommandMatchList function of libsymproc.so, imported by ctpd, has been identified in certain Crestron touch panels. This vulnerability may allow unauthorized execution of a file defined by an attacker, based on how the ConsoleFindCommandMatchList prioritizes file enumeration. The affected touch panels include the TSW-760 and TSW-1060 models, running firmware versions 3.002.1061, 3.000.0110.001, and earlier versions of 3.000.0110.001 for the x70 series.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2025CISA-ADP
Assessed Sep 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.crestron.com | Crestron Electronics, Inc. | Vendor |
| https://www.crestron.com/Software-Firmware/Firmware/Touchpanels/TS-770-TS-1070-TSS-770-TSS-1070-TSW-570/3-002-0040-001 | Crestron Electronics, Inc. | Permission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-697 | Incorrect Comparison | Crestron Electronics, Inc. |
Affected Products
| Product | Versions |
|---|---|
| Crestron TSW-760 | All versions |
CPE
Remediation
| |
| Crestron TSW-1060 | <= 3.000.0110.001 |
CPE
Remediation
| |
| Crestron TSW-770 | All versions |
CPE
Remediation
| |
| Crestron TSW-1070 | All versions |
CPE
Remediation
| |
| Crestron TSS-770 | All versions |
CPE
Remediation
| |
| Crestron TSS-1070 | All versions |
CPE
Remediation
| |
| Crestron TSW-570 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Crestron Electronics, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2025 | New CVE Received | Crestron Electronics, Inc. |
Volerion