CVE-2020-16839: Crestron Dm-Nvx-Dir-160 Firmware

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.

Affected products

  • Crestron Dm-Nvx-Dir-160 Firmware: version 1.0.1.788 only
  • Crestron Dm-Nvx-Dir-80 Firmware: version 1.0.1.788 only
  • Crestron Dm-Nvx-Dir-Ent Firmware: version 1.0.1.788 only

Published 2021-07-30. Last modified 2026-06-17.