Sensitive Information Exposure Vulnerability in Crestron Automate VX
CVE-2025-47417

5.1MEDIUM

Key Information:

Vendor

Crestron

Vendor
CVE Published:
6 May 2025

What is CVE-2025-47417?

A vulnerability exists in Crestron Automate VX that allows unauthorized access to sensitive information through stored video snapshots. When the 'Enable Debug Images' feature is activated, the software captures and saves images of video feeds locally without any visible notification. This could potentially expose sensitive visual data to unauthorized actors. Affected versions include Automate VX from 5.6.8161.21536 to 6.4.0.49, which underscores the necessity for users to remain vigilant about security settings and apply necessary updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Automate VX 5.6.8161.21536 <= 6.4.0.49

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Crestron Electronics Inc
.