Unauthorized File Download Vulnerability in Weintek cMT-3072XH2
CVE-2024-55019

6.5MEDIUM

Key Information:

Vendor

Weintek

Vendor
CVE Published:
3 March 2026

What is CVE-2024-55019?

The Weintek cMT-3072XH2 contains a vulnerability in its easyweb Web component, specifically in download_wb.cgi. This flaw allows an unprivileged user to access and download arbitrary files from the server. The weakness stems from a failure to verify user authorization before granting access to sensitive resources, posing a significant security risk to the integrity and confidentiality of the system. This vulnerability needs to be addressed promptly to prevent exploitation.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.