An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.
References
| Link | Resource |
|---|---|
| https://gist.github.com/AenganZ/f86ed0da28825a1432ec697f484622de | Third Party Advisory |
| https://plain-trick-71d.notion.site/weintek-cMT-3072XH2-14687a89c4c181eeb21ad61e0392f34b?pvs=4 | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-03-03 20:16
Updated : 2026-03-04 19:53
NVD link : CVE-2024-55026
Mitre link : CVE-2024-55026
CVE.ORG link : CVE-2024-55026
JSON object : View
Products Affected
weintek
- cmt-3072xh2_firmware
- easyweb
- cmt-3072xh2
CWE
CWE-256
Plaintext Storage of a Password
