Weintek cMT-3072XH2 Hardcoded FTP Password Vulnerability

Vulnerability

A vulnerability exists in the Weintek cMT-3072XH2 HMI device, specifically in easyweb version 2.1.53 and OS version 20231011. The vulnerability involves a hardcoded password in the FTP protocol, creating a persistent security risk as the password cannot be changed by users.

Impact

Exploitation of this vulnerability allows unauthorized access to the FTP service using the hardcoded credentials, potentially leading to unauthorized file transfers or manipulation.

Added: Mar 3, 2026, 8:37 PM
Updated: Mar 3, 2026, 10:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.