S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-3929 Scanner

CVE-2019-3929 scanner - OS Command Injection vulnerability in Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-3929
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4.by Crestron
Crestron AM-100 firmware 1.6.0.2
Updated Aug 21, 2026View on NVD →
Detail

Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4 are all wireless presentation systems that allow users to share content from their devices on a bigger screen. These devices are widely used in conference rooms, classrooms, and other large meeting spaces to enhance collaboration and productivity. They are designed to simplify the process of sharing content and enable users to present their ideas with ease.

The CVE-2019-3929 vulnerability detected in these devices is a command injection via the file_transfer.cgi HTTP endpoint. This means that an attacker can exploit this vulnerability to execute operating system commands as root, allowing them to gain full control of the device and potentially access sensitive information. This vulnerability can be accessed remotely and does not require authentication, making it a critical threat to the security of these devices.

When exploited, this vulnerability can lead to data theft, unauthorized access to confidential data, and even system downtime. It can also be used to install malware and other malicious software on the device, which can be used to launch further attacks against the user's network. This vulnerability can pose a significant risk to organizations that rely on these devices for their daily operations, making it crucial to take action to protect against it.

Thanks to the pro features of the s4e.io platform, users can quickly and easily identify and address vulnerabilities in their devices. The platform offers in-depth analysis and comprehensive reports on vulnerabilities, making it possible to detect and prevent threats before they can cause damage. By using this platform, users can stay ahead of evolving threats and keep their devices and networks secure.

 

REFERENCES

Solution Advice

Some precautions that can be taken to protect against this vulnerability include:

  • Updating the firmware of the affected devices to the latest version.
  • Limiting access to the file_transfer.cgi HTTP endpoint.
  • Disabling the file transfer feature completely if it is not necessary.
  • Implementing network segmentation to limit the attack surface.
  • Using intrusion detection and prevention systems to detect and block malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-3929 scanner - OS Command Injection vulnerability in Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4 | S4E