CVE-2025-47419: Crestron Automate Vx

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.

Affected products

  • Crestron Automate Vx: from 5.6.8161.21536, up to and including 6.4.0.49

Published 2025-05-06. Last modified 2026-06-17.