IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Weintek cMT3092X

HIGH
CVSS 8.8
Date 2026-07-23T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.

// Vulnerabilities (4)

CVE ID CVSS Score Severity Description
CVE-2026-61892 8.8 high
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
CVE-2026-60135 6.5 medium
An attacker can modify data that should be restricted to read‑only access.
CVE-2026-61886 6.5 medium
Weintek cMT3092X HMI stores user account passwords in plaintext.
CVE-2026-60134 8.8 high
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

// Remediations (2)

Mitigation: Weintek has published a document with more details about this issue at https://dl.weintek.com/public
Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.
Patch: Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains
Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.

// References