CVE-2024-55022

8.8

Weintek · cMT-3072XH2

Weintek cMT-3072XH2 easyweb v2.1.53 and OS v20231011 contain an authenticated command injection vulnerability via the HMI Name parameter.

Executive summary

An authenticated command injection vulnerability in Weintek cMT-3072XH2 devices allows an authenticated user to execute arbitrary commands, potentially leading to full system compromise.

Vulnerability

This vulnerability is a command injection flaw occurring within the HMI Name parameter. It requires the attacker to have established authenticated access to the device to trigger the injection of arbitrary system commands.

Business impact

The ability to perform command injection poses a severe risk to operational technology environments, as it allows for unauthorized control over the HMI device. With a CVSS score of 8.8, this flaw could lead to data manipulation, loss of process visibility, or complete system takeover, resulting in significant operational downtime and potential safety hazards.

Remediation

Immediate Action: Restrict access to the device management interface to trusted users only and monitor for any vendor-issued firmware updates.

Proactive Monitoring: Review system access logs for unusual administrative activity or suspicious strings within the HMI configuration settings.

Compensating Controls: Deploy network segmentation to isolate the HMI from non-essential network traffic and implement strict firewall rules to limit access to the device management interface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the linked research write-up.

Analyst recommendation

Given the high CVSS severity and the availability of technical details regarding the exploit mechanism, organizations should treat this vulnerability with high urgency. Administrators must restrict administrative access to the affected hardware and remain vigilant for official vendor patches to remediate the underlying command injection flaw.

More Weintek CVEs

Sources