← Back to browse · API

CVE-2018-5553

Severity
CRITICAL
CVSS
9.8
EPSS
0.02486
Risk score
40.07
CISA KEV
No
PoC
No
Published
2018-07-10
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2018-17322, GHSA-CHVW-4J9V-9X4R
Products
Crestron:DGE-100 unspecified ≤1.3384.00049.001, Crestron:DM-DGE-200-C unspecified ≤1.3384.00049.001, Crestron:TS-1542-C unspecified ≤1.3384.00049.001
Sources
euvd EUVD-2018-17322

Description

The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.

References