Authenticated Command Injection Vulnerability in Weintek cMT-3072XH2
CVE-2024-55022

8.8HIGH

Key Information:

Vendor

Weintek

Vendor
CVE Published:
3 March 2026

What is CVE-2024-55022?

The Weintek cMT-3072XH2 device has been found to be vulnerable to an authenticated command injection that can be exploited through the HMI Name parameter. This weakness allows an attacker with valid credentials to execute arbitrary commands, leading to potential compromise of the system's integrity and confidentiality. Users of the affected versions are encouraged to implement immediate security measures to mitigate the risk.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.