Vulnerability CVE-2022-23178


Published: 2022-01-15

Description:
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.

See advisories in our WLB2 database:
Topic
Author
Date
High
Crestron HD-MD4X2-4K-E 1.0.0.2159 Credential Disclosure
Anonymouse
12.01.2022
High
Creston Web Interface 1.0.0.2159 Credential Disclosure
RedTeam Pentesti...
18.01.2022

 References:
https://www.redteam-pentesting.de/advisories/rt-sa-2021-009

Copyright 2022, cxsecurity.com

 

Back to Top