Description
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Published: 2026-07-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Weintek’s cMT3092X HMI contains a flaw in the EasyWeb component that allows a non‑privileged user to alter authentication tokens, effectively bypassing the intended permission controls. This weakness, classified as CWE‑732, can elevate an attacker’s privileges from a basic user to full administrative rights, enabling unauthorized configuration changes and potential system compromise.

Affected Systems

Devices running the Weintek EasyWeb firmware or the cMT3092X model are affected. The vulnerability is present in the current firmware version supplied with the cMT3092X HMI and does not require a specific patch to be present before exploitation.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity of the flaw, while the EPSS score of less than 1% suggests a low but non‑zero chance of exploitation in the wild. The attack vector is likely local, through the HMI’s web interface or a directly connected interface, allowing a user with minimal access to modify the token settings. The vulnerability is not listed in the CISA KEV catalog, but the potential to achieve full administrative control warrants immediate remediation.

Generated by OpenCVE AI on August 3, 2026 at 19:40 UTC.

Remediation

Vendor Solution

Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support ( https://www.weintek.com/globalw/Support/Knowledge.aspx ) or from distributors.


OpenCVE Recommended Actions

  • Apply the Weintek patch package cmt_typeB_20260316_007.patch to update the EasyWeb firmware to version 2.3.17‑typeb, which removes the permission assignment flaw.
  • After applying the patch, re‑evaluate the web access controls and ensure that only authorized users have permission to modify authentication tokens; consider disabling unnecessary token modification features.
  • For systems that cannot be patched immediately, isolate the affected devices from external networks and monitor logs for any unauthorized token changes or privilege escalation attempts.

Generated by OpenCVE AI on August 3, 2026 at 19:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Weintek
Weintek cmt3092x Firmware
Weintek easyweb
Vendors & Products Weintek
Weintek cmt3092x Firmware
Weintek easyweb

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Title Weintek cMT3092X Incorrect Permission Assignment for Critical Resource
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Weintek Cmt3092x Firmware Easyweb
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-27T14:31:09.468Z

Reserved: 2026-07-16T16:04:55.185Z

Link: CVE-2026-61892

cve-icon Vulnrichment

Updated: 2026-07-27T14:31:06.284Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T23:16:51.333

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-61892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T19:45:07Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource