Privilege Escalation Vulnerability in Weintek cMT3092X HMI
CVE-2026-60134

8.7HIGH

Key Information:

Vendor

Weintek

Vendor
CVE Published:
24 July 2026

What is CVE-2026-60134?

The Weintek cMT3092X HMI is susceptible to a vulnerability that enables a non-privileged user to manipulate cookies. This exploitation can lead to unauthorized elevation of privileges, which may allow attackers to gain access to sensitive functions and data not typically available to them. Users of the cMT3092X HMI should consider applying available security updates and implement additional security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

cMT3092X firmware 0 < 20210218

EasyWeb 0

EasyWeb 2.3.17-typeb

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincenzo Giuseppe Colacino of Secoore reported this vulnerability to CISA.
.