Weintek cMT-3072XH2 FTP Credential Storage Vulnerability
Vulnerability
A vulnerability exists in the Weintek cMT-3072XH2 HMI device, specifically in easyweb version 2.1.53 and OS version 20231011. The vulnerability involves the storage of user credentials, including passwords, in plaintext within a local database file. This lack of encryption or hashing exposes sensitive authentication data, creating a risk if the database file is accessed.
Impact
Exploitation of this vulnerability leads to the exposure of user credentials, including passwords, allowing unauthorized access to the affected HMI system.
Added: Mar 3, 2026, 8:35 PM
Updated: Mar 3, 2026, 10:15 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
3.3remediation
0.0relevance
3.4threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
