Loading
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.
Use CWE-16, Crestron vendor hub and Am-100 Firmware product page to widen CVE-2019-3939 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-3929, CVE-2019-3932 and CVE-2019-3930 for nearby disclosures in the same product family.