Weintek kayıtları
weintek üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control3
- CWE-798 Use of Hard-coded Credentials3
- CWE-121 Stack-based Buffer Overflow2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-29 Path Traversal: '\..\filename'1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-27446İstismar yok | Weintek EasyWeb cMT Code Injectionweintek · cmt-svr-100 firmware · CWE-94 | Kritik9,8 | — | %2,9 | 16 May 2022 |
39İzleyin | CVE-2024-55020İstismar yok | A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attweintek · easyweb · CWE-20 | Kritik9,8 | — | %1,7 | 3 Mar 2026 |
39İzleyin | CVE-2021-27444İstismar yok | Weintek EasyWeb cMT Improper Access Controlweintek · cmt-svr-100 firmware · CWE-284 | Kritik9,8 | — | %1,2 | 16 May 2022 |
39İzleyin | CVE-2023-38584İstismar yok | Weintek cMT3000 HMI Web CGI Stack-based Buffer Overflowweintek · cmt-fhd firmware · CWE-121 | Kritik9,8 | — | %1,1 | 19 Eki 2023 |
39İzleyin | CVE-2023-43492İstismar yok | Weintek cMT3000 HMI Web CGI Stack-based Buffer Overflowweintek · cmt-fhd firmware · CWE-121 | Kritik9,8 | — | %0,9 | 19 Eki 2023 |
39İzleyin | CVE-2023-5777İstismar yok | Weintek EasyBuilder Pro Use of Hard-coded Credentialsweintek · easybuilder pro · CWE-798 | Kritik9,8 | — | %0,5 | 6 Kas 2023 |
39İzleyin | CVE-2024-55024İstismar yok | An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorizweintek · easyweb · CWE-693 | Kritik9,8 | — | %0,4 | 3 Mar 2026 |
39İzleyin | CVE-2024-55026İstismar yok | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrarweintek · easyweb · CWE-256 | Kritik9,8 | — | %0,3 | 3 Mar 2026 |
38İzleyin | CVE-2023-0104İstismar yok | The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file.weintek · easybuilder pro · CWE-29 | Yüksek7,8 | — | %21,8 | 22 Şub 2023 |
36İzleyin | CVE-2023-50466İstismar yok | An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arweintek · cmt2078x firmware · CWE-78 | Yüksek8,8 | — | %1,9 | 19 Ara 2023 |
35İzleyin | CVE-2024-55022İstismar yok | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Namweintek · easyweb · CWE-94 | Yüksek8,8 | — | %1,3 | 3 Mar 2026 |
35İzleyin | CVE-2023-40145İstismar yok | Weintek cMT3000 HMI Web CGI OS Command Injectionweintek · cmt-fhd firmware · CWE-78 | Yüksek8,8 | — | %1,2 | 19 Eki 2023 |
35İzleyin | CVE-2023-37362İstismar yok | Weintek Weincloud Improper Authenticationweintek · weincloud · CWE-522 | Yüksek8,8 | — | %0,6 | 19 Tem 2023 |
30İzleyin | CVE-2023-34429İstismar yok | Weintek Weincloud Improper Handling of Structural Elementsweintek · weincloud · CWE-237 | Yüksek7,5 | — | %0,7 | 19 Tem 2023 |
30İzleyin | CVE-2023-32657İstismar yok | Weintek Weincloud Improper Restriction of Excessive Authentication Attemptsweintek · weincloud · CWE-307 | Yüksek7,5 | — | %0,5 | 19 Tem 2023 |
30İzleyin | CVE-2024-55021İstismar yok | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.weintek · easyweb · CWE-798 | Yüksek7,5 | — | %0,3 | 3 Mar 2026 |
30İzleyin | CVE-2024-55019İstismar yok | Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthentiweintek · easyweb · CWE-284 | Yüksek7,5 | — | %0,3 | 3 Mar 2026 |
30İzleyin | CVE-2024-55027İstismar yok | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.weintek · easyweb · CWE-312 | Yüksek7,5 | — | %0,2 | 3 Mar 2026 |
26İzleyin | CVE-2024-55025İstismar yok | Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access tweintek · easyweb · CWE-284 | Orta6,5 | — | %0,3 | 3 Mar 2026 |
24İzleyin | CVE-2021-27442İstismar yok | Weintek EasyWeb cMT Cross-site Scriptingweintek · cmt-svr-100 firmware · CWE-79 | Orta6,1 | — | %0,9 | 16 May 2022 |
23İzleyin | CVE-2023-35134İstismar yok | Weintek Weincloud Weak Password Recovery Mechanism for Forgotten Passwordweintek · weincloud · CWE-640 | Orta5,9 | — | %0,5 | 19 Tem 2023 |
21İzleyin | CVE-2024-55023İstismar yok | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to accessweintek · easyweb · CWE-798 | Orta5,3 | — | %0,2 | 3 Mar 2026 |
- CVE-2021-2744640Planlayın
Weintek EasyWeb cMT Code Injection
KritikCVSS 9,8İstismar yokEPSS %3weintek · cmt-svr-100 firmware16 May 2022
- CVE-2024-5502039İzleyin
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows att
KritikCVSS 9,8İstismar yokEPSS %2weintek · easyweb3 Mar 2026
- CVE-2021-2744439İzleyin
Weintek EasyWeb cMT Improper Access Control
KritikCVSS 9,8İstismar yokEPSS %1weintek · cmt-svr-100 firmware16 May 2022
- CVE-2023-3858439İzleyin
Weintek cMT3000 HMI Web CGI Stack-based Buffer Overflow
KritikCVSS 9,8İstismar yokEPSS %1weintek · cmt-fhd firmware19 Eki 2023
- CVE-2023-4349239İzleyin
Weintek cMT3000 HMI Web CGI Stack-based Buffer Overflow
KritikCVSS 9,8İstismar yokEPSS %1weintek · cmt-fhd firmware19 Eki 2023
- CVE-2023-577739İzleyin
Weintek EasyBuilder Pro Use of Hard-coded Credentials
KritikCVSS 9,8İstismar yokEPSS %1weintek · easybuilder pro6 Kas 2023
- CVE-2024-5502439İzleyin
An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthoriz
KritikCVSS 9,8İstismar yokEPSS %0weintek · easyweb3 Mar 2026
- CVE-2024-5502639İzleyin
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrar
KritikCVSS 9,8İstismar yokEPSS %0weintek · easyweb3 Mar 2026
- CVE-2023-010438İzleyin
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file.
YüksekCVSS 7,8İstismar yokEPSS %22weintek · easybuilder pro22 Şub 2023
- CVE-2023-5046636İzleyin
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute ar
YüksekCVSS 8,8İstismar yokEPSS %2weintek · cmt2078x firmware19 Ara 2023
- CVE-2024-5502235İzleyin
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Nam
YüksekCVSS 8,8İstismar yokEPSS %1weintek · easyweb3 Mar 2026
- CVE-2023-4014535İzleyin
Weintek cMT3000 HMI Web CGI OS Command Injection
YüksekCVSS 8,8İstismar yokEPSS %1weintek · cmt-fhd firmware19 Eki 2023
- CVE-2023-3736235İzleyin
Weintek Weincloud Improper Authentication
YüksekCVSS 8,8İstismar yokEPSS %1weintek · weincloud19 Tem 2023
- CVE-2023-3442930İzleyin
Weintek Weincloud Improper Handling of Structural Elements
YüksekCVSS 7,5İstismar yokEPSS %1weintek · weincloud19 Tem 2023
- CVE-2023-3265730İzleyin
Weintek Weincloud Improper Restriction of Excessive Authentication Attempts
YüksekCVSS 7,5İstismar yokEPSS %1weintek · weincloud19 Tem 2023
- CVE-2024-5502130İzleyin
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
YüksekCVSS 7,5İstismar yokEPSS %0weintek · easyweb3 Mar 2026
- CVE-2024-5501930İzleyin
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenti
YüksekCVSS 7,5İstismar yokEPSS %0weintek · easyweb3 Mar 2026
- CVE-2024-5502730İzleyin
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.
YüksekCVSS 7,5İstismar yokEPSS %0weintek · easyweb3 Mar 2026
- CVE-2024-5502526İzleyin
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access t
OrtaCVSS 6,5İstismar yokEPSS %0weintek · easyweb3 Mar 2026
- CVE-2021-2744224İzleyin
Weintek EasyWeb cMT Cross-site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1weintek · cmt-svr-100 firmware16 May 2022
- CVE-2023-3513423İzleyin
Weintek Weincloud Weak Password Recovery Mechanism for Forgotten Password
OrtaCVSS 5,9İstismar yokEPSS %0weintek · weincloud19 Tem 2023
- CVE-2024-5502321İzleyin
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access
OrtaCVSS 5,3İstismar yokEPSS %0weintek · easyweb3 Mar 2026