Overview
Crestron Electronics DM-TXRX-100-STR, version 1.2866.00026 and earlier, has a web management interface which contains multiple vulnerabilities, including authentication bypass, failure to restrict access to authorized users, use of hard-coded certificate, default credentials, and cross-site request forgery (CSRF). These vulnerabilities may be leveraged to gain complete control of affected devices.
Description
| Crestron Electronics DM-TXRX-100-STR is a "streaming encoder/decoder designed to enable the distribution of high-definition AV signals over an IP network." The DM-TXRX-100-STR is configurable via a web interface that contains multiple vulnerabilities. CWE-603: Use of Client-Side Authentication - CVE-2016-5666 | 
Impact
| A remote, unauthenticated attacker may gain administrative access through numerous contexts to take complete control of vulnerable devices. | 
Solution
| Apply an upgrade | 
| Restrict network access and use strong passwords | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C | 
| Temporal | 8.3 | E:F/RL:OF/RC:C | 
| Environmental | 6.2 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND | 
References
- https://www.crestron.com/downloads/pdf/spec_sheets/commercial_and_residential/dm-txrx-100-str.pdf
- https://cwe.mitre.org/data/definitions/603.html
- http://cwe.mitre.org/data/definitions/425.html
- https://cwe.mitre.org/data/definitions/306.html
- https://cwe.mitre.org/data/definitions/321.html
- https://cwe.mitre.org/data/definitions/255.html
- https://cwe.mitre.org/data/definitions/352.html
- https://www.crestron.com/resources/resource-library/firmware
Acknowledgements
Thanks to Carsten Eiram of Risk Based Security for reporting these vulnerabilities.
This document was written by Joel Land.
Other Information
| CVE IDs: | CVE-2016-5666, CVE-2016-5667, CVE-2016-5668, CVE-2016-5669, CVE-2016-5670, CVE-2016-5671 | 
| Date Public: | 2016-08-01 | 
| Date First Published: | 2016-08-01 | 
| Date Last Updated: | 2016-08-01 16:05 UTC | 
| Document Revision: | 24 |