CVE-2024-55019

7.5

Weintek · cMT-3072XH2

An access control vulnerability in the download_wb.cgi component of Weintek cMT-3072XH2 allows unauthenticated attackers to download arbitrary files from the device.

Executive summary

A critical access control flaw in Weintek cMT-3072XH2 allows unauthenticated attackers to exfiltrate sensitive files, creating a significant risk of unauthorized information disclosure.

Vulnerability

The vulnerability exists in the download_wb.cgi component, which fails to perform necessary authentication checks. This allows any unauthenticated remote attacker to perform arbitrary file downloads from the underlying system.

Business impact

Successful exploitation of this vulnerability permits unauthorized access to sensitive system files, which may contain configuration data, credentials, or proprietary information. Given the CVSS score of 7.5, this high severity flaw poses a substantial threat to confidentiality and could lead to further system compromise or lateral movement within the operational technology environment.

Remediation

Immediate Action: Restrict network access to the affected cMT-3072XH2 web interface, ensuring it is not reachable from untrusted or public networks until a vendor-supplied patch is applied.

Proactive Monitoring: Review web server logs for suspicious requests targeting the download_wb.cgi endpoint, specifically monitoring for unusual file path traversal patterns or unauthorized access attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) to block requests containing path traversal sequences or unauthorized access attempts directed at the identified vulnerable CGI script.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the provided research references.

Analyst recommendation

Due to the unauthenticated nature of this vulnerability and the availability of proof-of-concept material, organizations using the Weintek cMT-3072XH2 should prioritize securing the device. Isolate the management interface from the internet and monitor for any anomalous traffic to the web component until an official software update is provided by the vendor.

More Weintek CVEs

Sources