Description
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Published: 2026-07-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Non‑privileged users can alter HTTP cookies used by the Weintek cMT3092X HMI to bypass security checks and obtain higher level privileges. The vulnerability arises from a lack of validation and integrity verification on cookie values, enabling an attacker to modify a cookie and cause the system to grant elevated access. This can lead to full control over the device and the underlying network, compromising confidentiality, integrity, and availability of the industrial control environment.

Affected Systems

The flaw targets Weintek EasyWeb and the cMT3092X firmware. No particular version range is listed; any deployment of these components that uses the default cookie handling may be impacted.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, yet the EPSS score is less than 1%, implying low current exploitation likelihood. The vulnerability is not yet in CISA’s KEV catalog. The likely attack path involves a user logging into the web interface, editing a cookie value, and triggering an authentication bypass. Because the attack requires only a basic account with web access, it is potentially exploitable in environments where monitoring of cookie changes is insufficient.

Generated by OpenCVE AI on August 3, 2026 at 19:39 UTC.

Remediation

Vendor Solution

Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support ( https://www.weintek.com/globalw/Support/Knowledge.aspx ) or from distributors.


OpenCVE Recommended Actions

  • Apply the cmt_typeB_20260316_007.patch package issued by Weintek to upgrade EasyWeb to 2.3.17‑typeb and address the cookie validation flaw
  • Reconfigure the HMI to perform cryptographic integrity checks on all cookie values, or disable cookie‑based authentication where feasible
  • Monitor web logs and cookie fields for anomalous modifications to detect potential exploitation attempts

Generated by OpenCVE AI on August 3, 2026 at 19:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Weintek
Weintek cmt3092x Firmware
Weintek easyweb
Vendors & Products Weintek
Weintek cmt3092x Firmware
Weintek easyweb

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Title Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision
Weaknesses CWE-784
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Weintek Cmt3092x Firmware Easyweb
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-27T14:30:33.224Z

Reserved: 2026-07-16T16:04:55.188Z

Link: CVE-2026-60134

cve-icon Vulnrichment

Updated: 2026-07-27T14:30:30.085Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T23:16:50.890

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-60134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T19:45:07Z

Weaknesses
  • CWE-784

    Reliance on Cookies without Validation and Integrity Checking in a Security Decision