CVE-2019-3929
Last modified
CVE-2019-3929 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.. CISA has confirmed active exploitation in the wild. EPSS estimates a 98.95% chance of exploitation in the next 30 days.
Description
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Crestron | Am-100 Firmware | 1.6.0.2 |
| Crestron | Am-101 Firmware | 2.7.0.2 |
| Barco | Wepresent Wipg-1000p Firmware | 2.3.0.10 |
| Barco | Wepresent Wipg-1600w Firmware | < 2.4.1.19 |
| Extron | Sharelink 200 Firmware | 2.0.3.4 |
| Extron | Sharelink 250 Firmware | 2.0.3.4 |
| Teqavit | Wips710 Firmware | 1.1.0.7 |
| Sharp | Pn-L703wa Firmware | 1.4.2.3 |
| Optoma | Wps-Pro Firmware | 1.0.0.5 |
| Blackbox | Hd Wireless Presentation System Firmware | 1.0.0.5 |
| Infocus | Liteshow3 Firmware | 1.0.16 |
| Infocus | Liteshow4 Firmware | 2.0.0.7 |
References
- https://packetstormsecurity.com/files/155948/Barco-WePresent-file_transfer.cgi-Command-Injection.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46786/Exploit, Third Party Advisory, VDB Entry
- https://www.tenable.com/security/research/tra-2019-20Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/155948/Barco-WePresent-file_transfer.cgi-Command-Injection.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46786/Exploit, Third Party Advisory, VDB Entry
- https://www.tenable.com/security/research/tra-2019-20Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3929US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2019-3929?
How severe is CVE-2019-3929?
How do I fix CVE-2019-3929?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3923Nessus versions 8.2.1 and earlier were found to contain a st…
- CVE-2019-3924MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-…7.5
- CVE-2019-3925Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…9.8
- CVE-2019-3926Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…9.8
- CVE-2019-3927Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…9.8
- CVE-2019-3928Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…5.3
- CVE-2019-3930The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmwa…9.8
- CVE-2019-3931Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…8.8
- CVE-2019-3932Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…9.8
- CVE-2019-3933Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…5.3
- CVE-2019-3934Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…5.3
- CVE-2019-3935Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmwa…9.1
Are you affected by CVE-2019-3929?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
