← All CVEs

CVE-2019-3929

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-04-15Remediation due 2022-05-06

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

9.8
CVSS
99.0%
EPSS (exploit prob.)
100th
EPSS percentile
2019-04-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-79CWE-78

Affected products

VendorProductAffected versions
crestronam-100_firmware1.6.0.2
crestronam-100all versions
crestronam-101_firmware2.7.0.2
crestronam-101all versions
barcowepresent_wipg-1000p_firmware2.3.0.10
barcowepresent_wipg-1000pall versions
barcowepresent_wipg-1600w_firmware< 2.4.1.19
barcowepresent_wipg-1600wall versions
extronsharelink_200_firmware2.0.3.4
extronsharelink_200all versions
extronsharelink_250_firmware2.0.3.4
extronsharelink_250all versions
teqavitwips710_firmware1.1.0.7
teqavitwips710all versions
sharppn-l703wa_firmware1.4.2.3
sharppn-l703waall versions
optomawps-pro_firmware1.0.0.5
optomawps-proall versions
blackboxhd_wireless_presentation_system_firmware1.0.0.5
blackboxhd_wireless_presentation_systemall versions
infocusliteshow3_firmware1.0.16
infocusliteshow3all versions
infocusliteshow4_firmware2.0.0.7
infocusliteshow4all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-3929