CVE-2019-3935
Description
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this vulnerability to start, stop, and disconnect active slideshows.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Crestron AM-100/AM-101 allow unauthenticated remote attackers to control slideshows via crafted HTTP POST requests to conference.cgi.
Vulnerability
The Crestron AM-100 (firmware 1.6.0.2) and AM-101 (firmware 2.7.0.2) contain a vulnerability in the conference.cgi endpoint. An attacker can send crafted HTTP POST requests to act as a moderator, allowing control over active slideshows [1]. The vulnerability is accessible without authentication or special configuration, making the code path reachable by any network entity that can reach the device's web interface.
Exploitation
A remote, unauthenticated attacker can exploit this vulnerability by sending specifically crafted HTTP POST requests to the conference.cgi endpoint. The attacker does not need any prior authentication, network position beyond reachability, or user interaction. By sending these requests, the attacker can issue moderator-level commands such as start, stop, and disconnect slideshows [1].
Impact
Successful exploitation enables an attacker to start, stop, and disconnect active slideshows on the affected Crestron devices. This constitutes a loss of availability for presentation functionality and may disrupt scheduled or ongoing presentations. The attacker does not gain code execution or access to other device functions, but the control over slideshows can cause operational disruption in meeting or conference room environments [1].
Mitigation
Crestron has not released a firmware update for the AM-100 or AM-101 to address this vulnerability as of the publication date. Users are advised to restrict network access to the affected devices, placing them behind firewalls or in segmented networks, and to disable or restrict access to the conference.cgi endpoint if feasible [1]. No workaround is explicitly provided in the reference.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Crestron/Crestron AirMediav5Range: AM-100 firmware 1.6.0.2 and AM-101 firmware 2.7.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- www.tenable.com/security/research/tra-2019-20mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.