Weintek cMT3092X

Summary

CISA has issued an alert regarding critical vulnerabilities in Weintek cMT3092X firmware and EasyWeb software. Successful exploitation could allow a non-privileged user to escalate privileges or view user credentials.

IFF Assessment

FOE

The identified vulnerabilities allow for privilege escalation and credential viewing, posing a direct threat to system security and user data.

Severity

8.8 High

The CVSS v3 score of 8.8 indicates a high severity. This is likely due to factors such as an easy attack vector (e.g., local access), the ability to escalate privileges, and potential for unauthorized access to sensitive information like credentials.

Defender Context

Defenders should prioritize patching affected Weintek cMT3092X devices and EasyWeb software to mitigate the risk of privilege escalation and credential theft. Monitoring for unusual cookie manipulation or unauthorized privilege changes on these industrial control systems is also crucial.

Read Full Story →