Crestron Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Crestron products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

1

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Crestron KEVs Added by Year

Loading...

2 Crestron KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-23178

An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed...

High Not in CISA 16 Sep 2025
CVE-2019-3929

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W...

Confirmed In CISA 15 Apr 2022

Common Vulnerability Classes (CWE)

  • CWE-287 — Improper Authentication 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology