Description
An attacker can modify data that should be restricted to read‑only access.
Published: 2026-07-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an instance of CWE-286, Improper Authorization, permitting attackers to modify information that should be read‑only. This unauthorized alteration can compromise device configuration and other critical parameters, leading to data integrity issues across the system.

Affected Systems

Weintek EasyWeb firmware operating on the cMT3092X hardware platform is affected. All installations of this EasyWeb component on the cMT3092X are potentially vulnerable, as no specific firmware versions are excluded.

Risk and Exploitability

The CVSS score of 7.1 marks the vulnerability as high severity, while the EPSS score of less than 1% indicates a very low probability of active exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is network‑based, targeting the device’s management interface or firmware update channel, with no additional prerequisites disclosed in the advisory.

Generated by OpenCVE AI on August 3, 2026 at 19:41 UTC.

Remediation

Vendor Solution

Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support ( https://www.weintek.com/globalw/Support/Knowledge.aspx ) or from distributors.


OpenCVE Recommended Actions

  • Request and apply the patch package named cmt_typeB_20260316_007.patch from Weintek support to upgrade EasyWeb to version 2.3.17‑typeb.
  • Confirm that write access is restricted to privileged accounts only and that the data previously affected by the vulnerability cannot be modified by normal users.
  • If immediate patching is not possible, restrict access to the device using firewalls or ACLs to reduce exposure until the update can be applied.

Generated by OpenCVE AI on August 3, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Weintek
Weintek cmt3092x Firmware
Weintek easyweb
Vendors & Products Weintek
Weintek cmt3092x Firmware
Weintek easyweb

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description An attacker can modify data that should be restricted to read‑only access.
Title Weintek cMT3092X Incorrect User Management
Weaknesses CWE-286
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Weintek Cmt3092x Firmware Easyweb
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-27T14:32:32.622Z

Reserved: 2026-07-16T16:04:55.177Z

Link: CVE-2026-60135

cve-icon Vulnrichment

Updated: 2026-07-27T14:32:29.316Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T23:16:51.037

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-60135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T19:45:07Z

Weaknesses
  • CWE-286

    Incorrect User Management