Junglewise Threat Intelligence

CVE-2026-61892: Weintek cMT3092X privilege escalation via token modification

CVE-2026-61892 · Severity: high · CVSS 8.8 · Published 2026-07-24

Technologies: Weintek EasyWeb, Weintek cMT3092X firmware. Vendors: Weintek.

Executive brief

Weintek cMT3092X Human-Machine Interface (HMI) devices, which are used to control industrial machinery, contain a security flaw that allows a user with low-level access to escalate their privileges. By modifying security tokens, an attacker could gain full control over the device's settings and operations. This could lead to unauthorized changes in industrial processes, data theft, or service disruptions in critical manufacturing environments.

Technical details

A privilege escalation vulnerability exists in Weintek cMT3092X HMI firmware and the EasyWeb component due to incorrect permission assignment for critical resources (CWE-732). An authenticated attacker with low-privileged network access can modify security tokens to gain elevated administrative rights. Successful exploitation allows the attacker to achieve full confidentiality, integrity, and availability impact on the affected HMI device. The vulnerability affects cMT3092X firmware versions prior to 20210218 and EasyWeb versions prior to v2.1.20. A patch (cmt_typeB_20260316_007.patch) is available from the vendor to update EasyWeb to version 2.3.17-typeb.

Affected products

  • Weintek cMT3092X firmware < 20210218
  • Weintek EasyWeb < v2.1.20

Timeline

  • 2026-07-23: advisory: CISA published ICSA-26-204-03
  • 2026-07-24: disclosed: CVE-2026-61892 published to NVD

References

Related threats