VYPR
Medium severityNVD Advisory· Published Sep 9, 2025· Updated Apr 15, 2026

CVE-2025-47415

CVE-2025-47415

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001.

Confirmed Affected Hardware: TSW-760, TSW-1060

Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued)

For x70

The Affected Firmware:- 3.000.0110.001  and versions below

The Fixed Firmware:- 3.001.0031.001

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A path traversal vulnerability in Crestron Touchscreens x70 allows relative path traversal, potentially exposing restricted files.

Vulnerability

Overview

CVE-2025-47415 is a path traversal vulnerability affecting Crestron Touchscreens x70 series, specifically the TSW-760 and TSW-1060 models. The issue stems from improper limitation of a pathname to a restricted directory, enabling relative path traversal attacks. Affected firmware versions include 3.000.0110.001 and below, while the fix is provided in firmware version 3.001.0031.001 [1].

Exploitation

Details

An attacker can exploit this vulnerability by crafting requests that traverse directories outside the intended restricted path. The attack does not require authentication, as the path traversal occurs through unauthenticated network requests. The vulnerability is accessible over the network, likely through services exposed on port 7000, as referenced in related security advisories [1].

Impact

Successful exploitation allows an attacker to read arbitrary files on the device, potentially including sensitive configuration data or credentials. This could lead to further compromise of the device or the network it resides on. The severity is rated as Medium, with a CVSS score reflecting the potential for information disclosure.

Mitigation

Crestron has released firmware version 3.001.0031.001 for the x70 series to address this vulnerability. Users are urged to update their devices to this version. For the TSW-760 and TSW-1060 models, which are confirmed affected, no fix has been released as the products are discontinued; users should consider replacing these devices or implementing network-level controls to limit exposure [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.