Impact
The flaw, identified as CWE‑256, allows user account passwords to be stored in plain text within the firmware configuration of the Weintek cMT3092X HMI, directly compromising confidentiality and enabling attackers to reuse credentials for unauthorized device access.
Affected Systems
The flaw affects the Weintek EasyWeb components and the cMT3092X firmware. All known releases run vulnerable code; no specific version numbers are quoted, so the entire product line should be treated as vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, yet the EPSS score of less than 1% suggests exploitation is currently low. The issue is not listed in CISA KEV, and the attacker is inferred to require local or network access to read the configuration files where passwords are stored.
OpenCVE Enrichment