highOther

Weintek cMT3092X HMI Multiple Vulnerabilities (Privilege Escalation, Plaintext Password Storage, Broken Access Control)

First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 8.8

ICSHMIvulnerabilityprivilege-escalationplaintext-passwordCWE-784CWE-732CWE-256CWE-286critical-manufacturingCISA-advisory

CISA disclosed four vulnerabilities in Weintek cMT3092X HMI devices and their EasyWeb web interface, allowing non-privileged users to escalate privileges via cookie/token manipulation, view plaintext-stored user credentials, and modify data that should be read-only. The highest-severity flaws (CVSS v3.1 8.8) enable full compromise of confidentiality, integrity, and availability on affected industrial control devices. No public exploitation has been reported, but a vendor patch is available.

Technical Analysis

CVE-2026-60134 and CVE-2026-61892 (CVSS 8.8) allow a non-privileged user to tamper with cookies and authentication tokens due to reliance on cookies without validation/integrity checking (CWE-784) and incorrect permission assignment (CWE-732), enabling privilege escalation to administrative access on the HMI's EasyWeb web management interface. CVE-2026-61886 (CVSS 6.5/7.1) stores user account passwords in plaintext (CWE-256), exposing credentials of all users to any party with local or network read access. CVE-2026-60135 (CWE-286, Incorrect User Management) permits modification of data intended to be read-only. These issues affect the network-facing web management interface of an industrial HMI, meaning exploitation requires only network access and low privileges (AV:N/AC:L/PR:L/UI:N). While these are OT/ICS-specific devices with no direct AI agent tooling involved, organizations that use AI agents or automation frameworks to monitor, orchestrate, or pull telemetry/credentials from HMI/SCADA web interfaces should treat any credentials or API tokens stored for such integrations as compromised if plaintext password stores are exposed, and should avoid granting agent-driven automation direct network access to unpatched HMI web interfaces.

Affected Systems

Weintek cMT3092X HMI firmware versions prior to 20210218; EasyWeb interface versions prior to v2.1.20

Indicators of Compromise

  • No known IOCs published; no public exploitation reported by CISA at this time.

Remediation Steps

  1. 1

    Apply vendor patch

    Obtain and install patch package cmt_typeB_20260316_007.patch (EasyWeb 2.3.17-typeb) from Weintek support or authorized distributors.

  2. 2

    Review vendor security bulletin

    Consult Weintek's TEC25003E document (dl.weintek.com) for detailed mitigation guidance specific to these EasyWeb V2 issues.

  3. 3

    Restrict network exposure

    Ensure HMI web management interfaces are not exposed to untrusted networks or the internet; segment ICS/OT networks from IT and agent/automation networks.

  4. 4

    Enforce least privilege

    Limit user accounts on the HMI to the minimum privileges necessary and audit existing accounts for unnecessary access.

  5. 5

    Rotate credentials

    Since passwords are stored in plaintext, rotate all HMI user credentials after patching and avoid credential reuse across systems, including any automation or agent integrations.

  6. 6

    Monitor for anomalous access

    Watch for unexpected cookie/token modifications or unauthorized privilege changes on affected devices.

CVE / Advisory IDs

CVE-2026-60134CVE-2026-61892CVE-2026-61886CVE-2026-60135

Industries Most Exposed

Critical ManufacturingIndustrial Control Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.