Loading vulnerabilities…
Loading vulnerabilities…
CVE-2026-61892
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
This record: live connection— last retrieved: 24 September 2026 at 05:11.
Taken directly from NVD, CISA or the vendor — sometimes in English, unchanged from the source.
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
NETWORK
Privileges required
LOW
User interaction
NONE
Confidentiality
High
Integrity
High
Availability
High
Probability of exploitation within 30 days
0.3%
Percentile
21e
Source: FIRST.org, updated on 23 September 2026.
Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.
Our own interpretation and context for the source data above.
IACS Radar assessment
Our own interpretation and context for this vulnerability — not an official source.
IACS Radar priority score
Based on CVSS 8.8, EPSS 0.3%, industrial relevance 60/100.
Combines CVSS, EPSS, KEV status, industrial relevance and exposure relevance — a complement to, not a replacement for, the individual scores below and above.
Conditions for exploitation
Operational impact & energy relevance
Possible loss of visibility of or control over the process upon successful exploitation.
Assessed as relevant to the energy sector based on: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Productbeschrijving komt overeen met de categorie "HMI", een typisch OT/ICS-componenttype.
Recommended defensive measures
Industrial relevance score
Automatically classified as industrially relevant based on CISA/NVD signals (see reasons).
Classified by IACS Radar-analysepijplijn (geautomatiseerd) on 24 September 2026.
IEC 62443 mapping
Automatic IACS Radar assessment based on the reported CWE weakness classification; not an official certification statement.