Impact
Non‑privileged users can alter HTTP cookies used by the Weintek cMT3092X HMI to bypass security checks and obtain higher level privileges. The vulnerability arises from a lack of validation and integrity verification on cookie values, enabling an attacker to modify a cookie and cause the system to grant elevated access. This can lead to full control over the device and the underlying network, compromising confidentiality, integrity, and availability of the industrial control environment.
Affected Systems
The flaw targets Weintek EasyWeb and the cMT3092X firmware. No particular version range is listed; any deployment of these components that uses the default cookie handling may be impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, yet the EPSS score is less than 1%, implying low current exploitation likelihood. The vulnerability is not yet in CISA’s KEV catalog. The likely attack path involves a user logging into the web interface, editing a cookie value, and triggering an authentication bypass. Because the attack requires only a basic account with web access, it is potentially exploitable in environments where monitoring of cookie changes is insufficient.
OpenCVE Enrichment