Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
1218045.8%CRITICAL

Related CVEs

18
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-55027Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.HIGH7.511.8%Mar 3, 2026
CVE-2024-55026An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.CRITICAL9.826.2%Mar 3, 2026
CVE-2024-55025Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.MEDIUM6.521.9%Mar 3, 2026
CVE-2024-55024An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.CRITICAL9.827.8%Mar 3, 2026
CVE-2024-55023Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.MEDIUM5.37.1%Mar 3, 2026
CVE-2024-55022Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.HIGH8.866.5%Mar 3, 2026
CVE-2024-55021Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.HIGH7.525.5%Mar 3, 2026
CVE-2024-55020A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.CRITICAL9.873.8%Mar 3, 2026
CVE-2024-55019Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.HIGH7.521.0%Mar 3, 2026
CVE-2023-50466An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.HIGH8.877.1%Dec 19, 2023
CVE-2023-5777 Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server. CRITICAL9.841.1%Nov 6, 2023
CVE-2023-43492 In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication. CRITICAL9.854.5%Oct 19, 2023
CVE-2023-40145 In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device. HIGH8.863.4%Oct 19, 2023
CVE-2023-38584 In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication. CRITICAL9.860.0%Oct 19, 2023
CVE-2023-37362Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.HIGH8.839.7%Jul 19, 2023
CVE-2023-35134 Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only. MEDIUM5.929.4%Jul 19, 2023
CVE-2023-34429 Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token. HIGH7.540.8%Jul 19, 2023
CVE-2023-32657 Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses. HIGH7.534.8%Jul 19, 2023