« Back to list

Weintek

Weintek Easyweb: vulnerabilities and CVEs

Weintek Easyweb has 9 published vulnerabilities, 9 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months9
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-55027High (7.5)0.22%—Mar 3, 2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.
CVE-2024-55026Critical (9.8)0.36%—Mar 3, 2026
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.
CVE-2024-55025Medium (6.5)0.31%—Mar 3, 2026
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.
CVE-2024-55024Critical (9.8)0.37%—Mar 3, 2026
An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.
CVE-2024-55023Medium (5.3)0.18%—Mar 3, 2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.
CVE-2024-55022High (8.8)1.3%—Mar 3, 2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.
CVE-2024-55021High (7.5)0.35%—Mar 3, 2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
CVE-2024-55020Critical (9.8)1.7%—Mar 3, 2026
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.
CVE-2024-55019High (7.5)0.30%—Mar 3, 2026
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application6
  2. T1059 Command and Scripting Interpreter3
  3. T1078.001 Default Accounts2
  4. T1005 Data from Local System1
  5. T1210 Exploitation of Remote Services1
  6. T1552.001 Credentials In Files1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Weintek