This content is restricted.
Brief
Summary:
This document provides an overview of a critical vulnerability in Weintek's cMT3000 HMI Web CGI device. The device has three vulnerabilities: a stack-based buffer overflow (CVSS v3 score 9.8) and two OS command injection vulnerabilities (CVSS v3 scores 9.8 and 8.8). These vulnerabilities allow an attacker to hijack control flow, bypass login authentication, and execute arbitrary commands. Affected products include cMT-FHD, cMT-HDM, cMT3071, cMT3072, cMT3103, cMT3090, and cMT3151. Weintek recommends updating these products to the latest versions, and CISA recommends minimizing network exposure, implementing firewalls, and using secure remote access methods. No public exploitation has been reported to date.
Highlights content goes here...
This content is restricted.
