VYPR

easyweb Web Version

by Weintek

CVEs (2)

  • CVE-2023-50466HigDec 19, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.

  • CVE-2024-55019HigMar 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.