← Back to browse · API

CVE-2025-47419

Severity
CRITICAL
CVSS
10.0
EPSS
0.00283
Risk score
40.1
CISA KEV
No
PoC
No
Published
2025-05-06
Modified
2025-05-07
First seen
2026-08-07
Aliases
EUVD-2025-13646, GHSA-49XP-C6GP-QWWW
Products
Crestron:Automate VX 5.6.8161.21536 ≤6.4.0.49
Sources
euvd EUVD-2025-13646

Description

Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.

References