An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0...
Critical severity
Unreviewed
Published
Jan 16, 2022
to the GitHub Advisory Database
•
Updated Mar 28, 2023
Description
Published by the National Vulnerability Database
Jan 15, 2022
Published to the GitHub Advisory Database
Jan 16, 2022
Last updated
Mar 28, 2023
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.
References