CVE-2026-60134 Details
Description
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
A vulnerability in the Weintek cMT3092X Human-Machine Interface (HMI) allows non-privileged users to alter cookies, potentially leading to unauthorized privilege escalation. This issue affects cMT3092X firmware versions prior to 20210218 and EasyWeb versions prior to v2.1.20.
Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which includes a newer EasyWeb version 2.3.17-typeb. This fix will be provided as a patch-only update, with no separate standard firmware release planned. Users can request the patch directly from Weintek support or through distributors.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf | [email protected] | Broken LinkVendor |
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-784 | Reliance on Cookies without Validation and Integrity Checking in a Security Decision | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Weintek cMT3092X | < 20210218 < v2.1.20 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion