Weintek cMT3092X
p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. /strong /p p The following versions of Weintek cMT3092X are affected: /p ul li cMT3092X firmware lt;20210218 nbsp; /li li EasyWeb lt;v2.1.20 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.8 /td td Weintek /td td Weintek cMT3092X /td td Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Taiwan /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-60134 /a /h3 div class= csaf-accordion-content p Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-60134 View CVE Details /a /p hr h4 Affected Products /h4 h5 Weintek cMT3092X /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Weintek /div div class= ics-version strong Product Version: /strong br Weintek cMT3092X firmware: lt;20210218, Weintek EasyWeb: lt;v2.1.20 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors. br a href= https://www.weintek.com/globalw/Support/Knowledge.aspx https://www.weintek.com/globalw/Support/Knowledge.aspx /a /p p strong Mitigation /strong br Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf. br a href= https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issue
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by CISA
Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.