GobyVuls/Crestron/CVE-2022-23178
2022-03-30 15:31:46 +08:00
..
2022-03-30 15:31:46 +08:00

Crestron Hd-Md4X2 Credential Disclosure (CVE-2022-23178)

restron Hd-Md4X2-4K-E is a simple-to-use UHD signal switcher with four HDMI inputs and two HDMI outputs from Crestron, USA.Crestron Hd-Md4X2-4K-E has an information disclosure vulnerability, attackers can obtain WEB user login credentials and further control the system.

FOFA query rule: body="js/top.js" && body="document.onmousedown = ReCalculate;"

Demo

MCMS_5_2_4_Arbitrary_File_Upload