CVE-2024-55024

8.8

Weintek · cMT-3072XH2 easyweb

An authentication bypass vulnerability in the Weintek cMT-3072XH2 easyweb authorization mechanism allows low-privileged users to perform unauthorized administrative actions.

Executive summary

A critical authentication bypass vulnerability in Weintek cMT-3072XH2 easyweb allows low-privileged attackers to escalate privileges and perform administrative actions.

Vulnerability

This flaw exists within the authorization mechanism, enabling an attacker with low-level privileges to bypass security controls. By leveraging service accounts, the attacker can execute commands or modifications reserved for administrative users.

Business impact

The ability for a low-privileged user to perform administrative functions poses a severe risk to the integrity and availability of the industrial control system. With a CVSS score of 8.8, this vulnerability allows for complete compromise of the affected unit, which could lead to unauthorized process manipulation, loss of operational control, or significant downtime.

Remediation

Immediate Action: Since a specific patch is not currently confirmed, administrators should restrict network access to the affected devices to trusted IP addresses only and disable unnecessary service accounts.

Proactive Monitoring: Review system logs for unusual administrative activity or unauthorized access attempts originating from low-privileged service accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) or equivalent network security policy to filter traffic and block attempts to invoke administrative functions via the web interface.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists as documented in the referenced GitHub Gist.

Analyst recommendation

Given the high CVSS severity and the availability of public exploit material, this vulnerability presents an immediate danger to operational environments. Organizations must prioritize segmenting these devices from the public internet and auditing all existing service accounts to ensure that administrative access is strictly controlled until the vendor provides a formal security update.

More Weintek CVEs

Sources