Weintek
Weintek Easyweb: vulnerabilities and CVEs
Weintek Easyweb has 9 published vulnerabilities, 9 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months9
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55027 | High (7.5) | 0.22% | — | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db. |
| CVE-2024-55026 | Critical (9.8) | 0.36% | — | Mar 3, 2026 | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request. |
| CVE-2024-55025 | Medium (6.5) | 0.31% | — | Mar 3, 2026 | Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system. |
| CVE-2024-55024 | Critical (9.8) | 0.37% | — | Mar 3, 2026 | An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts. |
| CVE-2024-55023 | Medium (5.3) | 0.18% | — | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information. |
| CVE-2024-55022 | High (8.8) | 1.3% | — | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter. |
| CVE-2024-55021 | High (7.5) | 0.35% | — | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol. |
| CVE-2024-55020 | Critical (9.8) | 1.7% | — | Mar 3, 2026 | A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges. |
| CVE-2024-55019 | High (7.5) | 0.30% | — | Mar 3, 2026 | Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.