CVE-2022-23178: Critical severity crestron hd-md4x2-4k-e firmware vulnerability
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23178?
CVE-2022-23178 is a vulnerability discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices that allows unauthorized access to user credentials through the administrative web interface.
How severe is CVE-2022-23178?
CVE-2022-23178 has a severity level of 9.8 (critical).
How does CVE-2022-23178 affect Crestron HD-MD4X2-4K-E devices?
CVE-2022-23178 affects Crestron HD-MD4X2-4K-E devices by exposing user credentials when the administrative web interface is accessed without authentication.
Is Crestron HD-MD4X2-4K-E 1.0.0.2159 firmware affected by CVE-2022-23178?
Yes, Crestron HD-MD4X2-4K-E 1.0.0.2159 firmware is affected by CVE-2022-23178.
How can I fix CVE-2022-23178?
There is currently no known fix for CVE-2022-23178. It is recommended to contact the vendor for updates or mitigation steps.