regulator
Weintek patches cMT3092X HMI privilege-escalation flaws
The fix ships as a standalone patch rather than a firmware update, and engineers must request it directly from Weintek support or distributors.
CISA published an ICS advisory Thursday for four vulnerabilities in the Weintek cMT3092X HMI, deployed in critical manufacturing worldwide. Two flaws (CVE-2026-60134, CVE-2026-61892) carry CVSS 8.8 scores and allow a low-privileged user to escalate to full system control via cookie or token manipulation. A third confirms plaintext password storage (CVE-2026-61886), and a fourth permits modification of read-only data (CVE-2026-60135). The fix, EasyWeb 2.3.17-typeb, bundled in patch cmt_typeB_20260316_007.patch, won't ship as a standard firmware release and must be requested from Weintek support or distributors.