CVE-2025-47415
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001.
Confirmed Affected Hardware: TSW-760, TSW-1060
Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued)
For x70
The Affected Firmware:- 3.000.0110.001 and versions below
The Fixed Firmware:- 3.001.0031.001
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path traversal vulnerability in Crestron Touchscreens x70 allows relative path traversal, potentially exposing restricted files.
Vulnerability
Overview
CVE-2025-47415 is a path traversal vulnerability affecting Crestron Touchscreens x70 series, specifically the TSW-760 and TSW-1060 models. The issue stems from improper limitation of a pathname to a restricted directory, enabling relative path traversal attacks. Affected firmware versions include 3.000.0110.001 and below, while the fix is provided in firmware version 3.001.0031.001 [1].
Exploitation
Details
An attacker can exploit this vulnerability by crafting requests that traverse directories outside the intended restricted path. The attack does not require authentication, as the path traversal occurs through unauthenticated network requests. The vulnerability is accessible over the network, likely through services exposed on port 7000, as referenced in related security advisories [1].
Impact
Successful exploitation allows an attacker to read arbitrary files on the device, potentially including sensitive configuration data or credentials. This could lead to further compromise of the device or the network it resides on. The severity is rated as Medium, with a CVSS score reflecting the potential for information disclosure.
Mitigation
Crestron has released firmware version 3.001.0031.001 for the x70 series to address this vulnerability. Users are urged to update their devices to this version. For the TSW-760 and TSW-1060 models, which are confirmed affected, no fix has been released as the products are discontinued; users should consider replacing these devices or implementing network-level controls to limit exposure [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.