Junglewise Threat Intelligence

CVE-2026-60135: Weintek cMT3092X Incorrect User Management in EasyWeb

CVE-2026-60135 · Severity: medium · CVSS 6.5 · Published 2026-07-24

Technologies: Weintek EasyWeb, Weintek cMT3092X firmware. Vendors: Weintek.

Executive brief

A vulnerability in Weintek cMT3092X industrial human-machine interface (HMI) devices allows an attacker to modify data that should be restricted to read-only access. These devices are commonly used in manufacturing environments to monitor and control industrial processes. If exploited, an unauthorized user could change critical operational settings or data, potentially leading to process disruptions or safety risks.

Technical details

The vulnerability is classified as CWE-286 (Incorrect User Management) within the EasyWeb component of Weintek cMT3092X HMI devices. An attacker with low-privileged network access can bypass intended access controls to modify data fields that are explicitly marked as read-only. This occurs due to insufficient validation of user permissions when processing data modification requests. Successful exploitation allows for unauthorized integrity changes to the device configuration or operational data. A patch (cmt_typeB_20260316_007.patch) is available from the vendor which updates EasyWeb to version 2.3.17-typeb.

Affected products

  • Weintek cMT3092X firmware <20210218
  • Weintek EasyWeb <v2.1.20

Timeline

  • 2026-07-23: advisory: CISA published advisory ICSA-26-204-03
  • 2026-07-24: disclosed: CVE-2026-60135 published to NVD

References

Related threats