VYPR
Vendor

Weintek

Products
10
CVEs
22
Across products
29
Status
Private

Products

10

Recent CVEs

22
View all 22 CVEs →
  • CVE-2021-27446CriMay 16, 2022
    risk 0.65cvss 10.0epss 0.03

    The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.

  • CVE-2023-5777CriNov 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.

  • CVE-2023-43492CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.

  • CVE-2023-38584CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.

  • CVE-2021-27444CriMay 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.

  • CVE-2023-0104CriFeb 22, 2023
    risk 0.62cvss 9.3epss 0.22

    The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  

  • CVE-2021-27442CriMay 16, 2022
    risk 0.61cvss 9.4epss 0.01

    The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.

  • CVE-2023-50466HigDec 19, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.

  • CVE-2023-40145HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.

  • CVE-2023-34429HigJul 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.

  • CVE-2023-35134HigJul 19, 2023
    risk 0.48cvss 7.4epss 0.00

    Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.

  • CVE-2023-37362HigJul 19, 2023
    risk 0.47cvss 7.2epss 0.01

    Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.

  • CVE-2023-32657MedJul 19, 2023
    risk 0.34cvss 5.3epss 0.00

    Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.

  • CVE-2024-55022Mar 3, 2026
    risk 0.00cvss epss 0.01

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.

  • CVE-2024-55024Mar 3, 2026
    risk 0.00cvss epss 0.00

    An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.

  • CVE-2024-55026Mar 3, 2026
    risk 0.00cvss epss 0.00

    An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.

  • CVE-2024-55025Mar 3, 2026
    risk 0.00cvss epss 0.00

    Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.

  • CVE-2024-55027Mar 3, 2026
    risk 0.00cvss epss 0.00

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

  • CVE-2024-55023Mar 3, 2026
    risk 0.00cvss epss 0.00

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.

  • CVE-2024-55021Mar 3, 2026
    risk 0.00cvss epss 0.00

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.