Weintek cMT3000 HMI Web CGI OS Command Injection
CVE-2023-40145
8.8HIGH
What is CVE-2023-40145?
The cMT3000 HMI Web CGI device by Weintek is vulnerable to arbitrary command execution, enabling an anonymous attacker to execute commands after gaining access to the device. This vulnerability can potentially lead to unauthorized actions being performed on the system, highlighting the need for robust security measures and timely updates to ensure device integrity.
Affected Version(s)
cMT-FHD 0 <= 20210210
cMT-HDM 0 <= 20210204
cMT3071 0 <= 20210218
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Hank Chen (PSIRT and Threat Research of TXOne Networks) reported these vulnerabilities to CISA.
