Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Easyweb CRITICAL 9.8
CVE-2024-55024

An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attack…

Mitigation only
Fix from $2,300 2026-03-03
Easyweb CRITICAL 9.8
CVE-2024-55026

An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary command…

Mitigation only
Fix from $2,300 2026-03-03
Easyweb HIGH 8.8
CVE-2024-55022

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name paramet…

Mitigation only
Fix from $1,950 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55021

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

Mitigation only
Fix from $1,950 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55027

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

Mitigation only
Fix from $1,950 2026-03-03
Easyweb MEDIUM 6.5
CVE-2024-55025

Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI sy…

Mitigation only
Fix from $1,600 2026-03-03
Easyweb MEDIUM 5.3
CVE-2024-55023

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitiv…

Mitigation only
Fix from $1,600 2026-03-03
Easyweb CRITICAL 9.8
CVE-2024-55020

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to…

Mitigation only
Fix from $2,300 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55019

Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated att…

Mitigation only
Fix from $1,950 2026-03-03
Cmt2078x Firmware HIGH 8.8
CVE-2023-50466

An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2023-12-19
Weincloud HIGH 8.8
CVE-2023-37362

Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official websi…

Mitigation only
Fix from $1,950 2023-07-19
Weincloud HIGH 7.5
CVE-2023-34429

Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.

No fix yet
Fix from $1,950 2023-07-19
Weincloud MEDIUM 5.9
CVE-2023-35134

Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.

Mitigation only
Fix from $1,600 2023-07-19
Weincloud HIGH 7.5
CVE-2023-32657

Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error…

Mitigation only
Fix from $1,950 2023-07-19