Junglewise Threat Intelligence

CVE-2026-61886: Weintek cMT3092X plaintext password storage in EasyWeb

CVE-2026-61886 · Severity: medium · CVSS 6.5 · Published 2026-07-24

Technologies: Weintek EasyWeb, Weintek cMT3092X firmware. Vendors: Weintek.

Executive brief

Weintek cMT3092X Human Machine Interface (HMI) devices, which are used to control industrial machinery, contain a security flaw where user passwords are stored without encryption. This allows an individual with basic network access to the device to view the login credentials of other users. If exploited, an attacker could gain unauthorized access to the control system, potentially leading to unauthorized changes in industrial operations or data theft.

Technical details

A plaintext storage of passwords vulnerability (CWE-256) exists in Weintek cMT3092X HMI firmware and the EasyWeb component. The vulnerability allows a non-privileged user with network access to the device to retrieve and view the credentials of other registered users because the system fails to use cryptographic hashing or encryption for stored passwords. This issue is part of a broader set of vulnerabilities (including privilege escalation via cookie/token manipulation) affecting these industrial control assets. A patch (cmt_typeB_20260316_007.patch) containing EasyWeb v2.3.17-typeb has been released to address the issue.

Affected products

  • Weintek cMT3092X firmware < 20210218
  • Weintek EasyWeb < v2.1.20

Timeline

  • 2026-07-23: advisory: CISA published advisory ICSA-26-204-03
  • 2026-07-24: disclosed: CVE-2026-61886 published to NVD

References

Related threats