Status: NEW | Advisory ID: CVE-2026-7865
| CVE | CVE-2026-7865 |
| CVSS Score / Version | 7.4 (High) / CVSS v4.0 |
| Updated | 2026-07-24 |
| Classified as | CWE-88 (Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')) |
A hidden console command is vulnerable to command injection
flaw when control characters are passed to its second argument.
A third party researcher Eugene Lim had discovered vulnerability
in the way console command passes to a popen function call. Attackers with
authenticated access to SSH console of Crestron devices may use to run
underlying OS commands. (NVD)
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-7865 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-7865 |