Loading
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.
Use Crestron vendor hub and Airmedia Am-100 Firmware product page to widen CVE-2019-3910 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-5640, CVE-2016-5639 and CVE-2017-16709 for nearby disclosures in the same product family.