Executive brief
Multiple presentation and collaboration products are vulnerable to unauthenticated remote command injection via the file_transfer.cgi HTTP endpoint. An attacker can exploit this to execute arbitrary operating system commands with root privileges.
Affected products
- Crestron AM-100 firmware 1.6.0.2
- Crestron AM-101 firmware 2.7.0.1
- Barco wePresent WiPG-1000P firmware 2.3.0.10
- Barco wePresent WiPG-1600W firmware before 2.4.1.19
- Extron ShareLink 200/250 firmware 2.0.3.4
- Teq AV IT WIPS710 firmware 1.1.0.7
- SHARP PN-L703WA firmware 1.4.2.3
- Optoma WPS-Pro firmware 1.0.0.5
- Blackbox HD WPS firmware 1.0.0.5
- InFocus LiteShow3 firmware 1.0.16
- InFocus LiteShow4 firmware 2.0.0.7
Timeline
- 2019-04-30: disclosed: Initial discovery/research published by Tenable (TRA-2019-20)
- 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-15: advisory