Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Easyweb CRITICAL 9.8
CVE-2024-55024

An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attack…

Mitigation only
Fix from $2,300 2026-03-03
Easyweb CRITICAL 9.8
CVE-2024-55026

An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary command…

Mitigation only
Fix from $2,300 2026-03-03
Easyweb HIGH 8.8
CVE-2024-55022

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name paramet…

Mitigation only
Fix from $1,950 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55021

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

Mitigation only
Fix from $1,950 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55027

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

Mitigation only
Fix from $1,950 2026-03-03
Easyweb MEDIUM 6.5
CVE-2024-55025

Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI sy…

Mitigation only
Fix from $1,600 2026-03-03
Easyweb MEDIUM 5.3
CVE-2024-55023

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitiv…

Mitigation only
Fix from $1,600 2026-03-03
Easyweb CRITICAL 9.8
CVE-2024-55020

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to…

Mitigation only
Fix from $2,300 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55019

Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated att…

Mitigation only
Fix from $1,950 2026-03-03
Cmt2078x Firmware HIGH 8.8
CVE-2023-50466

An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2023-12-19
Easybuilder Pro CRITICAL 9.8
CVE-2023-5777

Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finish…

Fix: 6.07.02 / 6.08.01.614+
Fix from $2,300 2023-11-06
Cmt Fhd Firmware CRITICAL 9.8
CVE-2023-38584

In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker t…

Fix: 20210206 / 20210212+
Fix from $2,300 2023-10-19
Cmt Fhd Firmware CRITICAL 9.8
CVE-2023-43492

In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to h…

Fix: 20210206 / 20210212+
Fix from $2,300 2023-10-19
Cmt Fhd Firmware HIGH 8.8
CVE-2023-40145

In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.

Fix: 20210206 / 20210212+
Fix from $1,950 2023-10-19
Weincloud HIGH 8.8
CVE-2023-37362

Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official websi…

Mitigation only
Fix from $1,950 2023-07-19
Weincloud HIGH 7.5
CVE-2023-34429

Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.

No fix yet
Fix from $1,950 2023-07-19
Weincloud MEDIUM 5.9
CVE-2023-35134

Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.

Mitigation only
Fix from $1,600 2023-07-19
Weincloud HIGH 7.5
CVE-2023-32657

Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error…

Mitigation only
Fix from $1,950 2023-07-19
Easybuilder Pro HIGH 7.8
CVE-2023-0104EPSS 22%

The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an …

Fix: 6.07.02.480 / 6.08.01.350+
Fix from $1,950 2023-02-22
Cmt Svr 100 Firmware CRITICAL 9.8
CVE-2021-27444

The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and do…

Fix: 20210209 / 20210222+
Fix from $2,300 2022-05-16
Cmt Svr 100 Firmware CRITICAL 9.8
CVE-2021-27446

The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privil…

Fix: 20210209 / 20210222+
Fix from $2,300 2022-05-16
Cmt Svr 100 Firmware MEDIUM 6.1
CVE-2021-27442

The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject ma…

Fix: 20210209 / 20210222+
Fix from $1,600 2022-05-16