CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-61886

criticalCVSS 6.5covered by 2 sourcesfirst seen 2026-07-23
View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected: cMT3092X firmware <20210218 EasyWeb <v2.1.20 CVSS Vendor Equipment Vulnerabilities v3 8.8 Weintek Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-60134 Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. View CVE Details Affected Products Weintek cMT3092X Vendor: Weintek Product Version: Weintek cMT3092X firmware: <20210218, Weintek EasyWeb: <v2.1.20 Product Status: known_affected Remediations Vendor fix Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors. https://www.weintek.com/globalw/Support/Knowledge.aspx Mitigation Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf. https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf Relevant CWE: CWE-784 Reliance on Cookies without Validation and Integrity Checking in a Security Decision Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N

CSIRTS triage

What
Vulnerabilities allow non-privileged users to escalate privileges or view other users' credentials.
Who is affected
Users of cMT3092X firmware versions prior to 20210218 and EasyWeb versions prior to v2.1.20.
Urgency
Remediation is critical due to the potential for privilege escalation.
Action
Update to the latest firmware and EasyWeb versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-61886

Get an email if CVE-2026-61886 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-61886

CVE.org record

Embed the live status

CVE-2026-61886 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-61886 status](https://www.csirts.com/badge/CVE-2026-61886)](https://www.csirts.com/cve/CVE-2026-61886)