CVE-2024-55027

7.5

Weintek · cMT-3072XH2 easyweb

The Weintek cMT-3072XH2 easyweb interface stores user credentials in plaintext within the uac_temp.db database file, allowing unauthorized access to sensitive information.

Executive summary

A critical vulnerability in Weintek cMT-3072XH2 devices allows unauthenticated attackers to retrieve plaintext credentials, posing a significant risk of unauthorized system access.

Vulnerability

The device suffers from a credential management flaw where sensitive authentication data is stored in cleartext within the uac_temp.db component. This vulnerability is accessible to unauthenticated attackers, as indicated by the CVSS vector AV:N/PR:N.

Business impact

The exposure of credentials in plaintext facilitates unauthorized access to the device and potentially the wider industrial network. This vulnerability carries a CVSS score of 7.5, reflecting a high risk of information disclosure that could lead to full system compromise, loss of operational control, and significant reputational damage.

Remediation

Immediate Action: Since a specific patch is not currently identified, administrators should restrict network access to the affected devices to trusted subnets only.

Proactive Monitoring: Monitor device logs for unusual file access patterns or unauthorized attempts to connect to the internal database components.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall or proxy to inspect and filter inbound traffic reaching the easyweb interface.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the provided researcher write-up and the associated GitHub Gist.

Analyst recommendation

Given the availability of a public proof-of-concept and the nature of the information disclosure, this vulnerability represents a significant security oversight. Organizations must isolate affected Weintek hardware from public networks immediately and maintain a heightened state of vigilance until the vendor provides a firmware update that ensures secure credential storage.

More Weintek CVEs

Sources