Impact
Weintek’s cMT3092X HMI contains a flaw in the EasyWeb component that allows a non‑privileged user to alter authentication tokens, effectively bypassing the intended permission controls. This weakness, classified as CWE‑732, can elevate an attacker’s privileges from a basic user to full administrative rights, enabling unauthorized configuration changes and potential system compromise.
Affected Systems
Devices running the Weintek EasyWeb firmware or the cMT3092X model are affected. The vulnerability is present in the current firmware version supplied with the cMT3092X HMI and does not require a specific patch to be present before exploitation.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of the flaw, while the EPSS score of less than 1% suggests a low but non‑zero chance of exploitation in the wild. The attack vector is likely local, through the HMI’s web interface or a directly connected interface, allowing a user with minimal access to modify the token settings. The vulnerability is not listed in the CISA KEV catalog, but the potential to achieve full administrative control warrants immediate remediation.
OpenCVE Enrichment