CVE-2021-27444
Estado: ModificadaCrítica (9.8)—
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.18%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (16)
Weintek — Cmt-ctrl01 FirmwareWeintek — Cmt-fhd FirmwareWeintek — Cmt-g01 FirmwareWeintek — Cmt-g02 FirmwareWeintek — Cmt-g03 FirmwareWeintek — Cmt-g04 FirmwareWeintek — Cmt-hdm FirmwareWeintek — Cmt-svr-100 FirmwareWeintek — Cmt-svr-102 FirmwareWeintek — Cmt-svr-200 FirmwareWeintek — Cmt-svr-202 FirmwareWeintek — Cmt3071 FirmwareWeintek — Cmt3072 FirmwareWeintek — Cmt3090 FirmwareWeintek — Cmt3103 FirmwareWeintek — Cmt3151 Firmware
CWE
- CWE-284
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-27444",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2021-27444",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-16T15:54:59.080295Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Weintek",
"product": "cMT-SVR-1xx/2xx",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "20210305",
"versionType": "custom"
}
]
},
{
"vendor": "Weintek",
"product": "cMT-G01/G02",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "20210209",
"versionType": "custom"
}
]
},
{
"vendor": "Weintek",
"product": "cMT-G03/G04",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "20210222",
"versionType": "custom"
}
]
},
{
"vendor": "Weintek",
"product": "cMT3071/cMT3072/cMT3090/cMT3103/cMT3151",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "20210218",
"versionType": "custom"
}
]
},
{
"vendor": "Weintek",
"product": "cMT-HDM",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "20210204",
"versionType": "custom"
}
]
},
{
"vendor": "Weintek",
"product": "cMT-FHD",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "20210208",
"versionType": "custom"
}
]
},
{
"vendor": "Weintek",
"product": "cMT-CTRL01",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "20210302",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-05-16T18:15:08.110",
"references": [
{
"url": "https://dl.weintek.com/public/Document/TEC/TEC21001E_cMT_EasyWeb_V1_Security_Issues.pdf",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-082-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://dl.weintek.com/public/Document/TEC/TEC21001E_cMT_EasyWeb_V1_Security_Issues.pdf",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-082-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator."
},
{
"lang": "es",
"value": "La línea de productos Weintek cMT es vulnerable a varios controles de acceso inapropiados, que pueden permitir a un atacante no autenticado acceder y descargar remotamente información confidencial y llevar a cabo acciones administrativas en nombre de un administrador legítimo"
}
],
"lastModified": "2026-06-17T03:44:52.327",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-svr-100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BD9FCBF-CD84-4863-A4E4-613BD228D2CA",
"versionEndExcluding": "20210305"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-svr-100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "408166F7-5030-4FDA-94CF-4DD2237A1EA7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-svr-102_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6D1FD50-6AD9-4F6F-84A2-1646542350CC",
"versionEndExcluding": "20210305"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-svr-102:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5EE3CBE0-6B56-4405-91E2-15DB0C6E7967"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-svr-200_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "176DF351-ECB2-44F8-9009-48B76D9EB867",
"versionEndExcluding": "20210305"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-svr-200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "673841CB-C2D6-486C-8C5D-0180173196D9"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-svr-202_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7AA6AD2-B144-437E-B185-4BD47703A54B",
"versionEndExcluding": "20210305"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-svr-202:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AB57299A-5F53-44A5-B1D3-2E554180562B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-g01_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5985D77C-E9BF-4E1B-8128-A0737281B8FA",
"versionEndExcluding": "20210209"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-g01:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E0ADA01D-E62C-4D53-B70D-BFB750CA2B52"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-g02_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BF566CC-966E-48E9-B6C9-F6CA52FFEAA1",
"versionEndExcluding": "20210209"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-g02:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1FB93C5F-4C71-4337-B72F-FE9B6E5CF83C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-g03_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F59201D7-3D0B-446F-90B9-FD19C9DB04C0",
"versionEndExcluding": "20210222"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-g03:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "61343FB6-5943-4FE7-9E3C-56F184622B7B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-g04_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F264AD39-4A3F-4273-A951-6DCB6768E82F",
"versionEndExcluding": "20210222"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-g04:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B2BCB236-F9AC-4729-BCAF-F005250C0F2E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt3071_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37D305D8-34F6-4BEF-99D4-CF4A18EFA9D3",
"versionEndExcluding": "20210218"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt3071:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A4DE53C8-09D5-4D5E-97EE-A89E1478CD65"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt3072_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A20906F-F91F-486A-9340-8D22C93C19AE",
"versionEndExcluding": "20210218"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt3072:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E3F83A8D-1489-48AA-911B-5BA561A57896"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt3090_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A84ABF9C-EC9B-4CBF-967F-5F38DCD32A16",
"versionEndExcluding": "20210218"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt3090:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "79C1F694-08A2-46E7-95C2-8DFA3D64423B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt3103_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B70E20F8-83E0-45C9-B02F-D1957AD47C6A",
"versionEndExcluding": "20210218"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt3103:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F607716E-7B7B-4620-819C-F44341B8C37F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt3151_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5065F83-0BD0-44B1-9E64-8689F0F3B4D0",
"versionEndExcluding": "20210218"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt3151:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9FF5326B-5E33-4C11-9AC6-A90357078FCA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-hdm_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A793B51-28F7-4A17-BD4C-74C2FCA053FC",
"versionEndExcluding": "20210204"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-hdm:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E08E3518-A03F-486D-B67A-013F67026D78"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-fhd_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81DBEE28-6A04-43E0-9C5E-592162179896",
"versionEndExcluding": "20210208"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-fhd:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A132B170-A1FC-4D38-9965-0FF47B944FD5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weintek:cmt-ctrl01_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38F4698D-B9D6-42E4-9867-9BDCC2F2F2A8",
"versionEndExcluding": "20210302"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weintek:cmt-ctrl01:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1C9CB899-1EE6-4599-861D-9BBA4856E5CE"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}