CVE-2026-7865 Details
Description
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A third party researcher Eugene Lim had discovered vulnerability in the way console command passes to a popen function call. Attackers with authenticated access to SSH console of Crestron devices may use to run underlying OS commands.
A command injection vulnerability has been identified in certain Crestron touch panel models, including the TSW-570, TSW-770, TSW-1070, TS-770, TS-1070, TSS-770, and TSS-1070. This vulnerability arises from a flaw in how a hidden console command processes control characters in its second argument, allowing authenticated attackers with SSH access to execute underlying operating system commands. The issue is present in firmware version 3.003.0015.001 and affects devices running Android 10 or 12.
Users can update their devices to the latest firmware version available through the Crestron Auto Update servers or via the Crestron Toolbox. For instructions on how to perform a manual update, refer to the Crestron Touch Panel Update Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.crestron.com/release_notes/tsw-xx70_3.003.0015.001_release_notes.pdf | Crestron Electronics, Inc. | |
| https://www.crestron.com/Software-Firmware/Firmware/Touchpanels/TS-770-TS-1070-TSS-770-TSS-1070-TSW-570/3-003-0015-001 | Crestron Electronics, Inc. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | Crestron Electronics, Inc. |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Crestron Electronics, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | New CVE Received | Crestron Electronics, Inc. |