← All Advisories

Crestron Hidden Console Command Passes Control Characters to popen, Letting Authenticated SSH Users Inject Underlying OS Commands

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-7865

Key Details

CVECVE-2026-7865
CVSS Score / Version7.4 (High) / CVSS v4.0
Updated2026-07-24
Classified asCWE-88 (Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'))

What to Know

A hidden console command is vulnerable to command injection

flaw when control characters are passed to its second argument. 

A third party researcher Eugene Lim had discovered vulnerability

in the way console command passes to a popen function call. Attackers with

authenticated access to SSH console of Crestron devices may use to run

underlying OS commands. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-7865
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-7865