Weintek patches cMT3092X HMI privilege-escalation flaws
The fix ships as a standalone patch rather than a firmware update, and engineers must request it directly from Weintek support or distributors.
TL;DR
CISA published an ICS advisory Thursday for four vulnerabilities in the Weintek cMT3092X HMI, deployed in critical manufacturing worldwide. Two flaws (CVE-2026-60134, CVE-2026-61892) carry CVSS 8.8 scores and allow a low-privileged user to escalate to full system control via cookie or token manipulation. A third confirms plaintext password storage (CVE-2026-61886), and a fourth permits modification of read-only data (CVE-2026-60135). The fix, EasyWeb 2.3.17-typeb, bundled in patch cmt_typeB_20260316_007.patch, won't ship as a standard firmware release and must be requested from Weintek support or distributors.
CISA published an ICS advisory Thursday covering four vulnerabilities in the Weintek cMT3092X HMI, a touch-panel device deployed in critical manufacturing environments worldwide. Two of the flaws, CVE-2026-60134 and CVE-2026-61892, carry CVSS 8.8 scores and let a low-privileged user escalate to full system control: one via cookie manipulation, the other via token modification. Both are network-exploitable and require no authentication beyond the initial low-privilege foothold.
The remaining two vulnerabilities are lower-severity but operationally significant. CVE-2026-61886 confirms the device stores user account passwords in plaintext, and CVE-2026-60135 allows an attacker to modify data that should be restricted to read-only access.
Weintek's fix comes as a standalone patch package, cmt_typeB_20260316_007.patch, rather than a standard firmware release. The patch bundles EasyWeb 2.3.17-typeb, which replaces the vulnerable EasyWeb versions below v2.1.20. Contractors running affected firmware, versions prior to 20210218, must request the patch directly from Weintek support or their distributors; it won't arrive through the normal update channel.
This is the sixth CISA ICS advisory for Weintek products since 2021, and the second this year targeting the cMT X series HMI EasyWeb service. The January 2026 advisory covered similar privilege-escalation and access-control flaws across the cMT3072XH, cMT-SVRX-820, and cMT-CTRL01 models.
Published ·Deep Fathom