CVE-2026-60134
- EPSS 0.32%
- Veröffentlicht 24.07.2026 22:20:20
- Zuletzt bearbeitet 30.07.2026 14:12:18
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
CVE-2026-61892
- EPSS 0.27%
- Veröffentlicht 24.07.2026 22:16:58
- Zuletzt bearbeitet 30.07.2026 14:12:18
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
CVE-2026-61886
- EPSS 0.23%
- Veröffentlicht 24.07.2026 22:10:03
- Zuletzt bearbeitet 30.07.2026 14:12:18
Weintek cMT3092X HMI stores user account passwords in plaintext.
CVE-2026-60135
- EPSS 0.21%
- Veröffentlicht 24.07.2026 22:06:12
- Zuletzt bearbeitet 30.07.2026 14:12:18
An attacker can modify data that should be restricted to read‑only access.
CVE-2024-55019
- EPSS 0.29%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 04.03.2026 20:10:31
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.
CVE-2024-55020
- EPSS 1.67%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 04.03.2026 20:03:26
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.
CVE-2024-55021
- EPSS 0.34%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 09.03.2026 18:20:11
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
CVE-2024-55022
- EPSS 1.29%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 09.03.2026 18:19:50
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.
CVE-2024-55023
- EPSS 0.17%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 09.03.2026 18:16:08
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.
CVE-2024-55024
- EPSS 0.36%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 04.03.2026 19:55:03
An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.