Weintek EasyWeb cMT Code Injection
CVE-2021-27446

10CRITICAL

What is CVE-2021-27446?

The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.

Affected Version(s)

cMT-CTRL01 < 20210302

cMT-FHD < 20210208

cMT-G01/G02 < 20210209

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcin Dudek from CERT.PL reported these vulnerabilities to CISA.
.