VYPR
advisoryPublished Jul 23, 2026· 1 source

Multiple Critical Vulnerabilities Discovered in Weintek cMT3092X HMIs

CISA has issued an advisory detailing several critical vulnerabilities in Weintek cMT3092X HMIs, potentially allowing privilege escalation and credential theft.

CISA has released an advisory highlighting multiple critical vulnerabilities affecting Weintek cMT3092X Human Machine Interface (HMI) devices. These flaws, if successfully exploited, could permit non-privileged users to escalate their privileges or gain access to the credentials of other users on the affected systems. The vulnerabilities span several categories, including reliance on cookies without proper validation, incorrect permission assignments, plaintext storage of passwords, and inadequate user management.

Specifically, CVE-2026-60134 allows a non-privileged user to modify cookies to achieve elevated privileges. Similarly, CVE-2026-61892 enables privilege escalation through the manipulation of tokens. A significant security weakness, identified as CVE-2026-61886, involves the plaintext storage of user account passwords, making them easily accessible to attackers who gain even limited access. Additionally, CVE-2026-60135 points to issues with data modification, where data intended to be read-only can be altered by an attacker, and CWE-286 (Incorrect User Management) further exacerbates these issues.

The affected products include Weintek cMT3092X firmware versions prior to 20210218 and EasyWeb versions earlier than v2.1.20. These devices are widely deployed in critical manufacturing sectors and are found globally, underscoring the potential impact of these vulnerabilities on industrial control systems. The CVSS v3.1 base score for the most severe vulnerabilities is rated at 8.8 (High), indicating a significant risk.

Weintek has provided a specific patch package, cmt_typeB_20260316_007.patch, which includes an updated version of EasyWeb (2.3.17-typeb). This patch is being delivered as a patch-only update, with no immediate plans for a separate standard firmware release. Users are advised to request this patch directly from Weintek support or their distributors.

In addition to the vendor fix, Weintek has also published a detailed mitigation document, available at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf, which provides further guidance on addressing these security concerns.

The vulnerabilities were reported to CISA by Vincenzo Giuseppe Colacino of Secoore. CISA emphasizes the importance of applying vendor-recommended patches and mitigations to protect industrial control systems from potential compromise. Organizations utilizing Weintek cMT3092X devices should prioritize the implementation of these security updates to prevent unauthorized access and potential operational disruptions.

Synthesized by Vypr AI