Weintek cMT-3072XH2 Hardcoded Encryption Key Vulnerability in easyweb

Vulnerability

A vulnerability exists in the Weintek cMT-3072XH2 HMI device running easyweb version 2.1.53 and OS version 20231011, due to a hardcoded encryption key. This key can potentially allow attackers to decrypt intercepted JSON communications and access sensitive system information. Additionally, the device stores user credentials in plaintext within local database files, further exposing sensitive data.

Impact

Exploitation of this vulnerability could lead to unauthorized access to decrypted communications, allowing interception of sensitive information. The plaintext storage of user credentials in database files also poses a significant security risk, as it exposes authentication data without any protection.

Added: Mar 3, 2026, 8:38 PM
Updated: Mar 3, 2026, 10:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.