VYPR
Vypr IntelligenceAI-generatedJul 23, 2026· 4 CVEs

Weintek cMT3092X HMI: Four Vulnerabilities Allow Privilege Escalation and Data Exposure

Four vulnerabilities affecting Weintek cMT3092X HMI disclosed, enabling privilege escalation and data access for non-privileged users.

Key findings

  • Four vulnerabilities in Weintek cMT3092X HMI disclosed on July 23, 2026.
  • Two high-severity flaws (CVSSv3 8.8) allow privilege escalation via cookie and token manipulation.
  • Medium-severity vulnerabilities include unauthorized data modification and plaintext password storage.
  • Affected firmware versions are <20210218 and EasyWeb <v2.1.20; patches are available.

On July 23, 2026, a batch of four vulnerabilities affecting the Weintek cMT3092X Human-Machine Interface (HMI) was disclosed. These vulnerabilities, detailed in CISA ICS Advisory ICSA-26-204-03, could allow a non-privileged user to escalate privileges or access user credentials. The disclosures highlight critical security weaknesses in industrial control systems, emphasizing the need for prompt patching and security reviews.

Two high-severity vulnerabilities, CVE-2026-60134 and CVE-2026-61892, stem from improper handling of user session tokens and cookies. CVE-2026-60134 specifically involves the modification of cookies to gain elevated privileges, while CVE-2026-61892 allows a non-privileged user to escalate privileges by manipulating tokens. These flaws, both rated with a CVSSv3 score of 8.8, present a significant risk of unauthorized access and control.

Additionally, two medium-severity vulnerabilities were disclosed. CVE-2026-60135, with a CVSSv3 score of 6.5, permits an attacker to modify data that should be restricted to read-only access. The other medium-severity vulnerability, CVE-2026-61886, also rated at 6.5, is due to the plaintext storage of user account passwords, making them easily accessible to anyone who gains even limited access to the system.

The affected versions include cMT3092X firmware prior to 20210218 and EasyWeb prior to v2.1.20. Weintek has addressed these issues through firmware and software updates. Users are strongly advised to update their systems to the patched versions to mitigate the risks associated with these vulnerabilities.

The coordinated disclosure of these vulnerabilities by CISA underscores the importance of securing industrial control systems. The ability for non-privileged users to escalate privileges or access sensitive credentials poses a direct threat to operational integrity and security in critical manufacturing and other sectors where these HMIs are deployed worldwide. Continuous monitoring and timely application of security patches are essential to protect against potential exploitation.

AI-written article. Grounded in 4 CVE records listed below.