← Vulnerability feed

Vulnerability record · CVE-2019-18826 · published 16 December 2019

CVE-2019-18826: Barco clickshare cs-100 firmware improper certificate validation vulnerability

BBarco · Clickshare Cs 100 Firmware

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not properly validate the whole certificate chain.

9.8 CVSS 3.1 Critical EPSS 0.68% · top 49.6% CWE-295 · Improper certificate validation
9.8CVSS 3.1 base score, v2 7.5
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not properly validate the whole certificate chain.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-18826 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-18830Barco clickshare cs-100 firmware os command injection vulnerabilityBarco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the function…EPSS 4.3%7.5CVE-2019-18825Barco clickshare cs-100 huddle firmware vulnerabilityBarco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Base Unit …EPSS 0.60%7.5CVE-2018-10943Barco clickshare cse-200 firmware improper input validation vulnerabilityAn issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP…EPSS 1.1%7.5CVE-2016-3151Barco clickshare csc-1 firmware path traversal vulnerabilityDirectory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devic…EPSS 4.3%6.8CVE-2019-18828Barco clickshare cs-100 firmware weak password requirements vulnerabilityBarco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug in…EPSS 0.39%6.1CVE-2016-3150Barco clickshare csc-1 firmware cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 dev…EPSS 1.3%5.9CVE-2019-18827Barco clickshare cs-100 firmware improper authorization vulnerabilityOn Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG…EPSS 1.4%5.3CVE-2019-18831Barco clickshare cs-100 firmware hard-coded credentials vulnerabilityBarco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private ke…EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2019-18826), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.