Weintek cMT3092X HMI Multiple Vulnerabilities (Privilege Escalation, Plaintext Password Storage, Broken Access Control)
First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 8.8
CISA disclosed four vulnerabilities in Weintek cMT3092X HMI devices and their EasyWeb web interface, allowing non-privileged users to escalate privileges via cookie/token manipulation, view plaintext-stored user credentials, and modify data that should be read-only. The highest-severity flaws (CVSS v3.1 8.8) enable full compromise of confidentiality, integrity, and availability on affected industrial control devices. No public exploitation has been reported, but a vendor patch is available.
Technical Analysis
CVE-2026-60134 and CVE-2026-61892 (CVSS 8.8) allow a non-privileged user to tamper with cookies and authentication tokens due to reliance on cookies without validation/integrity checking (CWE-784) and incorrect permission assignment (CWE-732), enabling privilege escalation to administrative access on the HMI's EasyWeb web management interface. CVE-2026-61886 (CVSS 6.5/7.1) stores user account passwords in plaintext (CWE-256), exposing credentials of all users to any party with local or network read access. CVE-2026-60135 (CWE-286, Incorrect User Management) permits modification of data intended to be read-only. These issues affect the network-facing web management interface of an industrial HMI, meaning exploitation requires only network access and low privileges (AV:N/AC:L/PR:L/UI:N). While these are OT/ICS-specific devices with no direct AI agent tooling involved, organizations that use AI agents or automation frameworks to monitor, orchestrate, or pull telemetry/credentials from HMI/SCADA web interfaces should treat any credentials or API tokens stored for such integrations as compromised if plaintext password stores are exposed, and should avoid granting agent-driven automation direct network access to unpatched HMI web interfaces.
Affected Systems
Weintek cMT3092X HMI firmware versions prior to 20210218; EasyWeb interface versions prior to v2.1.20
Indicators of Compromise
- No known IOCs published; no public exploitation reported by CISA at this time.
Remediation Steps
- 1
Apply vendor patch
Obtain and install patch package cmt_typeB_20260316_007.patch (EasyWeb 2.3.17-typeb) from Weintek support or authorized distributors.
- 2
Review vendor security bulletin
Consult Weintek's TEC25003E document (dl.weintek.com) for detailed mitigation guidance specific to these EasyWeb V2 issues.
- 3
Restrict network exposure
Ensure HMI web management interfaces are not exposed to untrusted networks or the internet; segment ICS/OT networks from IT and agent/automation networks.
- 4
Enforce least privilege
Limit user accounts on the HMI to the minimum privileges necessary and audit existing accounts for unnecessary access.
- 5
Rotate credentials
Since passwords are stored in plaintext, rotate all HMI user credentials after patching and avoid credential reuse across systems, including any automation or agent integrations.
- 6
Monitor for anomalous access
Watch for unexpected cookie/token modifications or unauthorized privilege changes on affected devices.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.