Crestron TSW-X60和MC3都是美国Crestron Electronics公司的产品。Crestron TSW-X60是一款交互式触摸屏设备。MC3是一款智能家居控制设备。 Crestron TSW-X60 2.001.0037.001之前版本和MC3 1.502.0047.00之前版本中存在安全漏洞,该漏洞源于具有常规权限的用户可以根据相关信息计算出sudo账号密码。攻击者可利用该漏洞执行隐藏的API调用并绕过CTP控制台沙盒环境。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Tool to exploit CVE-2018-13341 and recover hidden account password on Crestron devices | https://github.com/axcheron/crestron_getsudopwd | POC Details |
| 2 | This Tool Aims to Exploit the CVE-2018-13341 | https://github.com/Rajchowdhury420/CVE-2018-13341 | POC Details |
| 3 | This Tool Aims to Exploit the CVE-2018-13341 | https://github.com/RajChowdhury240/CVE-2018-13341 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-15190 | PHP Scripts Mall hotel-booking-script 跨站脚本漏洞 | |
| CVE-2018-15191 | PHP Scripts Mall hotel-booking-script 安全漏洞 | |
| CVE-2018-11492 | ASUS HG100 安全漏洞 | |
| CVE-2018-14028 | WordPress 安全漏洞 | |
| CVE-2018-14503 | Coremail XT 跨站脚本漏洞 | |
| CVE-2018-14837 | Wolf CMS 跨站脚本漏洞 | |
| CVE-2018-7754 | Linux kernel 日志信息泄露漏洞 | |
| CVE-2018-10769 | SmartMesh 安全漏洞 | |
| CVE-2018-15185 | PHP Scripts Mall Naukri/Shine/Jobsite Clone Script 安全漏洞 | |
| CVE-2018-15186 | PHP Scripts Mall Chartered Accountant:Auditor Website 跨站请求伪造漏洞 | |
| CVE-2018-15187 | PHP Scripts Mall advanced-real-estate-script 跨站请求伪造漏洞 | |
| CVE-2018-15188 | PHP Scripts Mall advanced-real-estate-script 安全漏洞 | |
| CVE-2018-15189 | PHP Scripts Mall advanced-real-estate-script 跨站脚本漏洞 | |
| CVE-2018-6553 | AppArmor cupsd Sandbox Bypass Due to Use of Hard Links | |
| CVE-2018-6556 | The lxc-user-nic component of LXC allows unprivileged users to open arbitrary files |
No comments yet