CVE-2024-55027
7.5Weintek · cMT-3072XH2 easyweb
The Weintek cMT-3072XH2 easyweb interface stores user credentials in plaintext within the uac_temp.db database file, allowing unauthorized access to sensitive information.
Executive summary
A critical vulnerability in Weintek cMT-3072XH2 devices allows unauthenticated attackers to retrieve plaintext credentials, posing a significant risk of unauthorized system access.
Vulnerability
The device suffers from a credential management flaw where sensitive authentication data is stored in cleartext within the uac_temp.db component. This vulnerability is accessible to unauthenticated attackers, as indicated by the CVSS vector AV:N/PR:N.
Business impact
The exposure of credentials in plaintext facilitates unauthorized access to the device and potentially the wider industrial network. This vulnerability carries a CVSS score of 7.5, reflecting a high risk of information disclosure that could lead to full system compromise, loss of operational control, and significant reputational damage.
Remediation
Immediate Action: Since a specific patch is not currently identified, administrators should restrict network access to the affected devices to trusted subnets only.
Proactive Monitoring: Monitor device logs for unusual file access patterns or unauthorized attempts to connect to the internal database components.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall or proxy to inspect and filter inbound traffic reaching the easyweb interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the provided researcher write-up and the associated GitHub Gist.
Analyst recommendation
Given the availability of a public proof-of-concept and the nature of the information disclosure, this vulnerability represents a significant security oversight. Organizations must isolate affected Weintek hardware from public networks immediately and maintain a heightened state of vigilance until the vendor provides a firmware update that ensures secure credential storage.