Weintek EasyWeb cMT Improper Access Control
CVE-2021-27444
9.8CRITICAL
What is CVE-2021-27444?
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.
Affected Version(s)
cMT-CTRL01 < 20210302
cMT-FHD < 20210208
cMT-G01/G02 < 20210209
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marcin Dudek from CERT.PL reported these vulnerabilities to CISA.
