← Back to home
ICSA-26-204-03  ·  Published 2026-07-23  ·  View on CISA ICS-CERT ↗

Weintek cMT3092X

CVSS 8.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.

Remediations

  • Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.
  • Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.

Affected Vendors

Weintek

Affected Products (2)

Weintek · cMT3092X firmware <20210218
Weintek · EasyWeb <v2.1.20

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more