Weintek cMT-3072XH2 FTP Credential Storage Vulnerability

Vulnerability

A vulnerability exists in the Weintek cMT-3072XH2 HMI device, specifically in easyweb version 2.1.53 and OS version 20231011. The vulnerability involves the storage of user credentials, including passwords, in plaintext within a local database file. This lack of encryption or hashing exposes sensitive authentication data, creating a risk if the database file is accessed.

Impact

Exploitation of this vulnerability leads to the exposure of user credentials, including passwords, allowing unauthorized access to the affected HMI system.

Added: Mar 3, 2026, 8:35 PM
Updated: Mar 3, 2026, 10:15 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.