CVE-2026-60135 Details
Description
An attacker can modify data that should be restricted to read‑only access.
A vulnerability exists in Weintek cMT3092X devices running firmware prior to 20210218 and in the cMT EasyWeb application versions through v2.1.20. This vulnerability allows an attacker to modify data that is meant to be read-only, potentially leading to unauthorized privilege escalation or access to other users' credentials.
Weintek has released a patch for this vulnerability, available as part of the cmt_typeB_20260316_007.patch package. This patch can be requested directly from Weintek support or through distributors. Additionally, Weintek has published a document detailing this issue, which is available on their website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf | [email protected] | Broken LinkVendor |
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03 | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-286 | Incorrect User Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Weintek cMT3092X | < 20210218 < v2.1.20 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion