As cited
Copy frozen at (site build).
vulnerabilities
Weintek cMT3092X
Weintek has disclosed three critical vulnerabilities in the cMT3092X human machine interface (HMI) device affecting firmware versions prior to 20210218 and EasyWeb versions below 2.1.20. The flaws enable non-privileged users to escalate privileges through cookie or token manipulation, and expose plaintext password storage. Weintek recommends applying patch cmt_typeB_20260316_007.patch containing EasyWeb 2.3.17-typeb, available through vendor support or distributors.
Why it matters: Industrial control system operators deploying cMT3092X devices face immediate privilege escalation and credential exposure risks; apply the available patch to critical manufacturing environments worldwide.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Weintek cMT3092X
Weintek has disclosed three critical vulnerabilities in the cMT3092X human machine interface (HMI) device affecting firmware versions prior to 20210218 and EasyWeb versions below 2.1.20. The flaws enable non-privileged users to escalate privileges through cookie or token manipulation, and expose plaintext password storage. Weintek recommends applying patch cmt_typeB_20260316_007.patch containing EasyWeb 2.3.17-typeb, available through vendor support or distributors.
Why it matters: Industrial control system operators deploying cMT3092X devices face immediate privilege escalation and credential exposure risks; apply the available patch to critical manufacturing environments worldwide.
- Source published
- First seen by Cybersecurity Tracker