Weintek vulnerabilities
3 CVEs tracked
Weintek appears in recent reports within the context of critical vulnerabilities affecting its cMT3092X HMI model. Key events involve privilege escalation by non-privileged users through token and cookie manipulation (CVE-2026-61892, CVE-2026-60134), as well as the storage of user account passwords in plaintext on the device (CVE-2026-61886). Defenders should immediately update these Human-Machine Interface (HMI) devices with the latest manufacturer-supplied firmware, enforce strict access control policies against privilege escalation, and account for potential credential compromise due to the plaintext password storage risk.
Azərbaycanca: Weintek, son hesabatlarda cMT3092X HMI modeli ilə bağlı kritik zəifliklər kontekstində görünür. Əsas hadisələr aşağı imtiyazlı istifadəçinin token və cookie-ləri manipulyasiya edərək imtiyazlarını artırması (CVE-2026-61892, CVE-2026-60134) və cihazda istifadəçi şifrələrinin düz mətn halında saxlanması (CVE-2026-61886) ilə bağlıdır. Müdafiəçilər bu İnsan-Maşın İnterfeysi (HMI) cihazlarını dərhal istehsalçının ən son proqram təminatı ilə yeniləməli, imtiyaz artımına qarşı ciddi giriş nəzarəti siyasətləri tətbiq etməli və düz mətn şifrə saxlanması riski səbəbindən potensial etimadnamə sızmasını nəzərə almalıdırlar.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Weintek: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.