Weintek cMT-3072XH2 VNC Authorization Bypass Vulnerability
Vulnerability
An authenticated command injection vulnerability has been identified in the Weintek cMT-3072XH2 HMI product, specifically in easyweb version 2.1.53 and OS version 20231011. The vulnerability arises from improper input validation in the HMI name parameter, allowing authenticated users to inject commands that are executed with elevated privileges after a system reboot. This exploitation could lead to unauthorized access and control over the HMI system and the industrial processes it manages.
Impact
Exploitation of this vulnerability allows for unauthorized VNC access using built-in service accounts, bypassing authorization checks and enabling control over the HMI interface.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
