{"document":{"acknowledgments":[{"names":["Vincenzo Giuseppe Colacino"],"organization":"Secoore","summary":"reported these vulnerabilities to CISA"}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"text":"Disclosure is not limited","tlp":{"label":"WHITE","url":"https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage"}},"lang":"en-US","notes":[{"category":"legal_disclaimer","text":"This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).","title":"Legal Notice and Terms of Use"},{"category":"summary","text":"Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.","title":"Advisory Summary"},{"category":"other","text":"Critical Manufacturing","title":"Critical infrastructure sectors"},{"category":"other","text":"Worldwide","title":"Countries/areas deployed"},{"category":"other","text":"Taiwan","title":"Company headquarters location"},{"category":"general","text":"CISA recommends users take the following measures to protect themselves from social engineering attacks:","title":"Recommended Practices"},{"category":"general","text":"Practice principles of least privilege.","title":"Recommended Practices"},{"category":"general","text":"Do not click web links or open attachments in unsolicited email messages.","title":"Recommended Practices"},{"category":"general","text":"Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.","title":"Recommended Practices"},{"category":"general","text":"Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.","title":"Recommended Practices"},{"category":"general","text":"CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.","title":"Recommended Practices"},{"category":"general","text":"CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.","title":"Recommended Practices"},{"category":"general","text":"CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.","title":"Recommended Practices"},{"category":"general","text":"Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.","title":"Recommended Practices"},{"category":"general","text":"Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.","title":"Recommended Practices"},{"category":"general","text":"No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.","title":"Recommended Practices"}],"publisher":{"category":"coordinator","contact_details":"central@cisa.dhs.gov","name":"CISA","namespace":"https://www.cisa.gov/"},"references":[{"category":"self","summary":"ICS Advisory ICSA-26-204-03 JSON","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-03.json"},{"category":"self","summary":"ICSA Advisory ICSA-26-204-03 - Web Version","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/uscert/ncas/tips/ST04-014"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/topics/industrial-control-systems"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing"},{"category":"external","summary":"Recommended Practices","url":"https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks"}],"title":"Weintek cMT3092X","tracking":{"current_release_date":"2026-07-23T06:00:00.000000Z","generator":{"date":"2026-07-22T17:12:41.646110Z","engine":{"name":"CISA CSAF Generator","version":"1.0.0"}},"id":"ICSA-26-204-03","initial_release_date":"2026-07-23T06:00:00.000000Z","revision_history":[{"date":"2026-07-23T06:00:00.000000Z","legacy_version":"Initial","number":"1","summary":"Initial Publication"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<20210218","product":{"name":"Weintek cMT3092X firmware: <20210218","product_id":"CSAFPID-0001"}}],"category":"product_name","name":"cMT3092X firmware"},{"branches":[{"category":"product_version_range","name":"<v2.1.20","product":{"name":"Weintek EasyWeb: <v2.1.20","product_id":"CSAFPID-0002"}}],"category":"product_name","name":"EasyWeb"}],"category":"vendor","name":"Weintek"}]},"vulnerabilities":[{"cve":"CVE-2026-60134","cwe":{"id":"CWE-784","name":"Reliance on Cookies without Validation and Integrity Checking in a Security Decision"},"notes":[{"category":"summary","text":"Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.","title":"Vulnerability Summary"},{"category":"details","text":"SSVCv2/E:N/A:N/2026-07-22T06:00:00.000000Z","title":"SSVC"}],"product_status":{"known_affected":["CSAFPID-0001","CSAFPID-0002"]},"references":[{"category":"external","summary":"cwe.mitre.org","url":"https://cwe.mitre.org/data/definitions/784.html"},{"category":"external","summary":"www.cve.org","url":"https://www.cve.org/CVERecord?id=CVE-2026-60134"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"remediations":[{"category":"vendor_fix","details":"Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb.  This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.","product_ids":["CSAFPID-0002"],"url":"https://www.weintek.com/globalw/Support/Knowledge.aspx"},{"category":"mitigation","details":"Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.","product_ids":["CSAFPID-0001","CSAFPID-0002"],"url":"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-0001","CSAFPID-0002"]}]},{"cve":"CVE-2026-61892","cwe":{"id":"CWE-732","name":"Incorrect Permission Assignment for Critical Resource"},"notes":[{"category":"summary","text":"Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.","title":"Vulnerability Summary"},{"category":"details","text":"SSVCv2/E:N/A:N/2026-07-22T06:00:00.000000Z","title":"SSVC"}],"product_status":{"known_affected":["CSAFPID-0001","CSAFPID-0002"]},"references":[{"category":"external","summary":"cwe.mitre.org","url":"https://cwe.mitre.org/data/definitions/732.html"},{"category":"external","summary":"www.cve.org","url":"https://www.cve.org/CVERecord?id=CVE-2026-61892"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"remediations":[{"category":"vendor_fix","details":"Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb.  This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.","product_ids":["CSAFPID-0002"],"url":"https://www.weintek.com/globalw/Support/Knowledge.aspx"},{"category":"mitigation","details":"Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.","product_ids":["CSAFPID-0001","CSAFPID-0002"],"url":"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-0001","CSAFPID-0002"]}]},{"cve":"CVE-2026-61886","cwe":{"id":"CWE-256","name":"Plaintext Storage of a Password"},"notes":[{"category":"summary","text":"Weintek cMT3092X HMI stores user account passwords in plaintext.","title":"Vulnerability Summary"},{"category":"details","text":"SSVCv2/E:N/A:N/2026-07-22T06:00:00.000000Z","title":"SSVC"}],"product_status":{"known_affected":["CSAFPID-0001","CSAFPID-0002"]},"references":[{"category":"external","summary":"cwe.mitre.org","url":"https://cwe.mitre.org/data/definitions/256.html"},{"category":"external","summary":"www.cve.org","url":"https://www.cve.org/CVERecord?id=CVE-2026-61886"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"remediations":[{"category":"vendor_fix","details":"Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb.  This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.","product_ids":["CSAFPID-0002"],"url":"https://www.weintek.com/globalw/Support/Knowledge.aspx"},{"category":"mitigation","details":"Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.","product_ids":["CSAFPID-0001","CSAFPID-0002"],"url":"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["CSAFPID-0001","CSAFPID-0002"]}]},{"cve":"CVE-2026-60135","cwe":{"id":"CWE-286","name":"Incorrect User Management"},"notes":[{"category":"summary","text":"An attacker can modify data that should be restricted to read‑only access.","title":"Vulnerability Summary"},{"category":"details","text":"SSVCv2/E:N/A:N/2026-07-22T06:00:00.000000Z","title":"SSVC"}],"product_status":{"known_affected":["CSAFPID-0001","CSAFPID-0002"]},"references":[{"category":"external","summary":"cwe.mitre.org","url":"https://cwe.mitre.org/data/definitions/286.html"},{"category":"external","summary":"www.cve.org","url":"https://www.cve.org/CVERecord?id=CVE-2026-60135"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},{"category":"external","summary":"www.first.org","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}],"remediations":[{"category":"vendor_fix","details":"Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb.  This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.","product_ids":["CSAFPID-0002"],"url":"https://www.weintek.com/globalw/Support/Knowledge.aspx"},{"category":"mitigation","details":"Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.","product_ids":["CSAFPID-0001","CSAFPID-0002"],"url":"https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["CSAFPID-0001","CSAFPID-0002"]}]}]}