PT-2026-22779 · Weintek · Cmt-3072Xh2+1

Published

2026-03-03

·

Updated

2026-03-04

·

CVE-2024-55022

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weintek cMT-3072XH2 easyweb version 2.1.53, OS version 20231011
Description The software contains an authenticated command injection issue. The issue is triggered via the HMI Name parameter. An attacker with valid credentials can inject commands.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-55022

Affected Products

Cmt-3072Xh2
Easyweb