CVE-2018-11229: Crestron Toolbox Protocol Firmware

Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.

Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP).

Affected products

  • Crestron Crestron Toolbox Protocol Firmware: before 2.001.0037.001 (fixed in 2.001.0037.001)

Published 2018-06-08. Last modified 2026-06-17.