CVE-2024-55021

7.5

Weintek · cMT-3072XH2

The Weintek cMT-3072XH2 easyweb interface and OS contain a hardcoded password within the FTP protocol, allowing unauthorized access.

Executive summary

A hardcoded password vulnerability in the Weintek cMT-3072XH2 FTP service poses a significant risk of unauthorized remote data access.

Vulnerability

The device contains a hardcoded password within the FTP service implementation, which allows unauthenticated remote attackers to gain unauthorized access to the system.

Business impact

The presence of a hardcoded credential allows any remote attacker to bypass authentication mechanisms and access sensitive system configurations or data stored on the device. Given the CVSS score of 7.5, this high severity vulnerability could result in total compromise of the affected industrial interface, potentially leading to operational disruption or unauthorized data exfiltration.

Remediation

Immediate Action: Since no specific patch is currently identified, isolate the affected device from the public internet and disable the FTP service if it is not required for essential operations.

Proactive Monitoring: Monitor network traffic for unauthorized FTP login attempts and review system logs for any access patterns originating from unknown or unauthorized IP addresses.

Compensating Controls: Implement strict network segmentation or place the device behind a firewall that restricts access to the FTP port to only trusted management workstations.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the referenced researcher write-up and GitHub Gist.

Analyst recommendation

Organizations utilizing the Weintek cMT-3072XH2 should treat this as a high priority security issue. Because the vulnerability involves a hardcoded credential, the only effective mitigation is to remove network access to the vulnerable service until the vendor provides a firmware update that removes the hardcoded password.

More Weintek CVEs

Sources