Junglewise Threat Intelligence

CVE-2026-7865: Crestron Touchpanels command injection in hidden console command

CVE-2026-7865 · Severity: info · CVSS 7.4 · Published 2026-05-05

Executive brief

Crestron Touchpanels, which are used for controlling enterprise and residential automation systems, contain a vulnerability in a hidden maintenance command. An attacker who already has administrative access to the device's command-line interface can exploit this flaw to take full control of the underlying operating system. This could lead to unauthorized access to the local network or disruption of the building's control systems.

Technical details

A command injection vulnerability exists in a hidden console command within Crestron Touchpanels (x60/x70 series). The flaw is rooted in the improper neutralization of argument delimiters (CWE-88) when input is passed to a 'popen' function call. An attacker with authenticated SSH access can inject control characters into the second argument of this hidden command to execute arbitrary system commands with the privileges of the application. The vulnerability was addressed in firmware version 3.003.0015.001.

Affected products

  • Crestron Electronics Touchpanels (x60/x70) 3.002.0043.001 through 3.003.0015.001

Timeline

  • 2026-05-05: disclosed
  • 2026-05-05: advisory
  • 2026-06-17: patched: Firmware 3.003.0015.001 confirmed as unaffected version.

References