← Back

Weintek

weintek

22 CVEs • 39 products

Products (39)

Click to collapse
Toggle
Easyweb
easyweb
Weincloud
weincloud
Cmt Svr 100
cmt-svr-100
Cmt Svr 102
cmt-svr-102
Cmt Svr 200
cmt-svr-200
Cmt Svr 202
cmt-svr-202
Cmt G01
cmt-g01
Cmt G02
cmt-g02
Cmt G03
cmt-g03
Cmt G04
cmt-g04
Cmt3071
cmt3071
Cmt3072
cmt3072
Cmt3090
cmt3090
Cmt3103
cmt3103
Cmt3151
cmt3151
Cmt Hdm
cmt-hdm
Cmt Fhd
cmt-fhd
Cmt Ctrl01
cmt-ctrl01
Cmt2078x
cmt2078x
Cmt 3072xh2
cmt-3072xh2

CVEs (22)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.
1Weintek
2Cmt 3072xh2 Firmware
Easyweb
Jun 17, 2026
Mar 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.
1Weintek
1Cmt2078x Firmware
Jun 17, 2026
Dec 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload int...Show more
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.Show less
1Weintek
1Easybuilder Pro
Jun 17, 2026
Nov 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in...Show more
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server. Show less
1Weintek
7Cmt Fhd Firmware
Cmt Hdm FirmwareCmt3071 Firmware+4 more
Jun 17, 2026
Oct 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
1Weintek
7Cmt Fhd Firmware
Cmt Hdm FirmwareCmt3071 Firmware+4 more
Jun 17, 2026
Oct 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.
1Weintek
7Cmt Fhd Firmware
Cmt Hdm FirmwareCmt3071 Firmware+4 more
Jun 17, 2026
Oct 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
1Weintek
1Weincloud
Jun 17, 2026
Jul 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
1Weintek
1Weincloud
Jun 17, 2026
Jul 19, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.
1Weintek
1Weincloud
Jun 17, 2026
Jul 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.
1Weintek
1Weincloud
Jun 17, 2026
Jul 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.
1Weintek
1Easybuilder Pro
Jun 17, 2026
Feb 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sens...Show more
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.   Show less
1Weintek
16Cmt Ctrl01 Firmware
Cmt Fhd FirmwareCmt G01 Firmware+13 more
Jun 17, 2026
May 16, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.