Crestron Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Crestron products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
2
In CISA KEV
1
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Crestron KEVs Added by Year
Loading...
2 Crestron KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-23178
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed... |
HD-MD4X2-4K-E | High | Not in CISA | 16 Sep 2025 |
|
CVE-2019-3929
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W... |
Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4. | Confirmed | In CISA | 15 Apr 2022 |
Common Vulnerability Classes (CWE)
- CWE-287 — Improper Authentication 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology