Security & Threat Intelligence · 23.07.2026, 18:07 UTC
Weintek cMT3092X
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories · CISA Advisories ↗ |
| Veröffentlicht | 23.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-60134, CVE-2026-60135, CVE-2026-61886, CVE-2026-61892. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected:
cMT3092X firmware <20210218 EasyWeb <v2.1.20
CVSS Vendor Equipment Vulnerabilities
v3 8.8 Weintek Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan
Vulnerabilities
Expand All +
CVE-2026-60134
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. View CVE Details
Affected Products Weintek cMT3092X
Vendor:Weintek Product Version:Weintek cMT3092X firmware: <20210218, Weintek EasyWeb: <v2.1.20 Product Status:known_affected
Remediations Vendor fixWeintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.https://www.weintek.com/globalw/Support/Knowledge.aspx MitigationWeintek has published a document with more details about this issue at …