Description
Weintek cMT3092X HMI stores user account passwords in plaintext.
Published: 2026-07-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw, identified as CWE‑256, allows user account passwords to be stored in plain text within the firmware configuration of the Weintek cMT3092X HMI, directly compromising confidentiality and enabling attackers to reuse credentials for unauthorized device access.

Affected Systems

The flaw affects the Weintek EasyWeb components and the cMT3092X firmware. All known releases run vulnerable code; no specific version numbers are quoted, so the entire product line should be treated as vulnerable until patched.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, yet the EPSS score of less than 1% suggests exploitation is currently low. The issue is not listed in CISA KEV, and the attacker is inferred to require local or network access to read the configuration files where passwords are stored.

Generated by OpenCVE AI on August 4, 2026 at 14:50 UTC.

Remediation

Vendor Solution

Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support ( https://www.weintek.com/globalw/Support/Knowledge.aspx ) or from distributors.


OpenCVE Recommended Actions

  • Request and install the cmt_typeB_20260316_007.patch from Weintek support to upgrade EasyWeb to 2.3.17‑typeb, which resolves the CWE‑256 plaintext storage weakness by implementing secure password handling.
  • Review the Weintek security issue document at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf for detailed information about the vulnerability and patch guidance.
  • Backup the existing configuration files before applying the patch to preserve the previous state and facilitate remediation.
  • After the update, audit the configuration to confirm that passwords are no longer stored in plain text and remove any legacy password entries that might persist, thereby ensuring compliance with secure storage practices.

Generated by OpenCVE AI on August 4, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Weintek
Weintek cmt3092x Firmware
Weintek easyweb
Vendors & Products Weintek
Weintek cmt3092x Firmware
Weintek easyweb

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Weintek cMT3092X HMI stores user account passwords in plaintext.
Title Weintek cMT3092X Plaintext Storage of a Password
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Weintek Cmt3092x Firmware Easyweb
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-27T14:32:07.257Z

Reserved: 2026-07-16T16:04:55.182Z

Link: CVE-2026-61886

cve-icon Vulnrichment

Updated: 2026-07-27T14:32:04.056Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T23:16:51.197

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-61886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:00:14Z

Weaknesses
  • CWE-256

    Plaintext Storage of a Password