CVE-2025-47418 Details
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
A vulnerability in Crestron Automate VX, versions 5.6.8161.21536 through 6.4.0.49, allows for the unauthorized exposure of sensitive information and misuse of functionality. The issue arises because there is no visible indication when the system is recording, and recording can be enabled remotely via a network API.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 6, 2025CISA-ADP
Assessed May 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.crestron.com/ | Crestron Electronics, Inc. | Vendor |
| https://www.crestron.com/release_notes/automate_vx_6.4.1.8_release_notes.pdf | Crestron Electronics, Inc. | Release NotesVendor |
| https://www.crestron.com/Software-Firmware/Software/Automate-VX-Software/6-4-1-8 | Crestron Electronics, Inc. | Permission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | Crestron Electronics, Inc. |
Affected Products
| Product | Versions |
|---|---|
| Crestron Automate VX | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Crestron Electronics, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2025 | New CVE Received | Crestron Electronics, Inc. |
Volerion