Weintek
weintek
22 CVEs • 39 products
Products (39)
Click to collapseToggle
Products (39)
Click to collapse
CVEs (22)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db. |
1Weintek 2Cmt 3072xh2 Firmware EasywebJun 17, 2026 Mar 3, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request. |
1Weintek 2Cmt 3072xh2 Firmware EasywebJun 17, 2026 Mar 3, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system. |
1Weintek 2Cmt 3072xh2 Firmware EasywebJun 17, 2026 Mar 3, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts. |
1Weintek 2Cmt 3072xh2 Firmware EasywebJun 17, 2026 Mar 3, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information. |
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter. |
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol. |
1Weintek 2Cmt 3072xh2 Firmware EasywebJun 17, 2026 Mar 3, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges. |
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files. |
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload int...Show more |
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in...Show more |
1Weintek 7Cmt Fhd Firmware Cmt Hdm FirmwareCmt3071 Firmware+4 moreJun 17, 2026 Oct 19, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
|
1Weintek 7Cmt Fhd Firmware Cmt Hdm FirmwareCmt3071 Firmware+4 moreJun 17, 2026 Oct 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2
In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.
|
1Weintek 7Cmt Fhd Firmware Cmt Hdm FirmwareCmt3071 Firmware+4 moreJun 17, 2026 Oct 19, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
|
Weintek Weincloud v0.13.6
could allow an attacker to abuse the registration functionality to login with testing credentials to the official website. |
Weintek Weincloud v0.13.6
could allow an attacker to reset a password with the corresponding account’s JWT token only.
|
Weintek Weincloud v0.13.6
could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.
|
Weintek Weincloud v0.13.6
could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.
|
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sens...Show more |
1Weintek 16Cmt Ctrl01 Firmware Cmt Fhd FirmwareCmt G01 Firmware+13 moreJun 17, 2026 May 16, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system. |