Vulnerability record · CVE-2022-23178 · published 15 January 2022
CVE-2022-23178: Crestron HDMI switcher web interface leaks admin credentials unauthenticated
Crestron · Hd Md4x2 4k E Firmware
The Crestron HD-MD4X2-4K-E HDMI switcher exposes administrative credentials through its web interface without requiring authentication. The aj.html endpoint returns a JSON document containing uname and upassword fields, so anyone who can reach the device can obtain valid login credentials. This matters because the leaked credentials grant full control of the device's administrative interface.
Description
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable disclosure of valid administrative credentials with a CVSS score of 9.8 and very high EPSS probability.
What it is
The Crestron HD-MD4X2-4K-E HDMI switcher exposes administrative credentials through its web interface without requiring authentication. The aj.html endpoint returns a JSON document containing uname and upassword fields, so anyone who can reach the device can obtain valid login credentials. This matters because the leaked credentials grant full control of the device's administrative interface.
Impact
An attacker gains working administrative credentials for the web interface, allowing configuration changes and control of the HDMI switcher. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network via the device's administrative web interface; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The aj.html endpoint returns the credential JSON to any requester.
Exploitation
Not listed in CISA KEV, but EPSS is 0.75159 (99.485th percentile), indicating a high predicted likelihood of exploitation activity. Both references are tagged Exploit and Third Party Advisory, so public exploit detail exists.
What to do
- Apply the vendor firmware update for the HD-MD4X2-4K-E; the record does not state a fixed version, so confirm with Crestron.
- Restrict network access to the device web interface to trusted management networks only.
- Change any credentials exposed by the device and audit for prior unauthorized logins.
- If the device cannot be patched or isolated, disable or block the administrative web interface.
- Monitor vendor advisories for updated remediation guidance.
Detection
- Search web/proxy logs for requests to aj.html on Crestron device IPs.
- Alert on unauthenticated access to the device administrative interface from unexpected sources.
- Review device authentication logs for logins using the leaked credentials or from unusual hosts.
- Inventory internet- or broadly reachable Crestron HDMI switchers on the network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.redteam-pentesting.de/advisories/rt-sa-2021-009 | ExploitThird Party Advisory |
| https://www.redteam-pentesting.de/advisories/rt-sa-2021-009 | ExploitThird Party Advisory |
Track CVE-2022-23178 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23178), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.