Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote attackers to obtain access by setting the value of objresp.authenabled to 1. <a href"http://cwe.mitre.org/data/definitions/603.html">CWE-603: Use of Client-Side Authentication</a>
Publication date: Mon, 15 Aug 2016 20:18:00 +0000