CVE-2026-7865EPSS p61.1%
CVE-2026-7865CVE-2026-7865
Description
A hidden console command is vulnerable to command injection
flaw when control characters are passed to its second argument.
A third party researcher Eugene Lim had discovered vulnerability
in the way console command passes to a popen function call. Attackers with
authenticated access to SSH console of Crestron devices may use to run
underlying OS commands.
Scoring
| EPSS | 0.98% probability of exploitation · percentile 61.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-24 |