Data Modification Vulnerability in Weintek cMT EasyWeb
CVE-2026-60135
7.1HIGH
What is CVE-2026-60135?
The cMT EasyWeb platform by Weintek is subject to a vulnerability that allows attackers to alter data that is intended to be read-only. This flaw poses a significant risk as it can lead to unauthorized changes in critical system information, undermining data integrity and potentially leading to further exploitation. Users are urged to apply necessary security measures to fortify their systems against such unauthorized access.
Affected Version(s)
cMT3092X firmware 0 < 20210218
EasyWeb 0
EasyWeb 2.3.17-typeb
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vincenzo Giuseppe Colacino of Secoore reported this vulnerability to CISA.
