Plaintext Credential Storage Vulnerability in Weintek cMT-3072XH2
CVE-2024-55027

7.5HIGH

Key Information:

Vendor

Weintek

Vendor
CVE Published:
3 March 2026

What is CVE-2024-55027?

The Weintek cMT-3072XH2 devices are affected by a vulnerability that stores sensitive user credentials in plaintext within the uac_temp.db component. This flaw exposes credentials to unauthorized access, potentially allowing malicious actors to gain access to user accounts and sensitive data. Proper measures should be implemented to safeguard stored credentials and avoid risks associated with plaintext storage.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.