Impact
The flaw is an instance of CWE-286, Improper Authorization, permitting attackers to modify information that should be read‑only. This unauthorized alteration can compromise device configuration and other critical parameters, leading to data integrity issues across the system.
Affected Systems
Weintek EasyWeb firmware operating on the cMT3092X hardware platform is affected. All installations of this EasyWeb component on the cMT3092X are potentially vulnerable, as no specific firmware versions are excluded.
Risk and Exploitability
The CVSS score of 7.1 marks the vulnerability as high severity, while the EPSS score of less than 1% indicates a very low probability of active exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is network‑based, targeting the device’s management interface or firmware update channel, with no additional prerequisites disclosed in the advisory.
OpenCVE Enrichment