Weintek cMT3092X
Weintek’s cMT3092X HMI and EasyWeb software versions are vulnerable to privilege escalation and credential exposure. A non-privileged user can modify cookies to gain elevated privileges, and user passwords are stored in plaintext. Weintek recommends applying a patch (cmt_typeB_20260316_007.patch) to address these issues, which are currently unexploited in the wild.
Weintek’s cMT3092X HMI and EasyWeb software versions are vulnerable to security flaws that could allow an attacker to gain unauthorized access and escalate privileges. Specifically, a non-privileged user can manipulate cookies to gain elevated permissions within the system. Furthermore, user account passwords are stored in plaintext, creating a significant risk of compromise. Weintek has published a document detailing the vulnerabilities and providing a patch (cmt_typeB_20260316_007.patch) for users to apply. The patch is available for request from Weintek support or distributors. CISA recommends users implement principles of least privilege and avoid clicking unsolicited links or opening attachments. At the time of this advisory, no public exploits targeting these vulnerabilities have been reported.