Back to Database
Status published
Critical
CVE-2019-3926
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2...
Vulnerability Description
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3926
Credits & Attribution
No credits recorded in the NVD database.
More from Crestron
View All →CVE-2025-47420
User Permissions on Network API
High
8.7
CVE-2025-47419
Non-Secure Access
Critical
10
CVE-2025-47418
Recording
Medium
5.3
CVE-2025-47417
Enable Debug Images
Medium
5.1
CVE-2023-6926
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Crestron AM-300
High
8.4
Affected Vendor
Crestron
View all reports →Affected Software
Crestron AirMedia
Vulnerable Versions:
AM-100 firmware 1.6.0.2 and AM-101 firmware 2.7.0.2
Timeline
Official Publish:
April 30th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H