Vulnerabilities (CVE)

Filtered by vendor Weintek Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50466 1 Weintek 2 Cmt2078x, Cmt2078x Firmware 2023-12-29 N/A 8.8 HIGH
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.
CVE-2023-37362 1 Weintek 1 Weincloud 2023-07-26 N/A 8.8 HIGH
Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
CVE-2023-34429 1 Weintek 1 Weincloud 2023-07-26 N/A 7.5 HIGH
Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.
CVE-2023-32657 1 Weintek 1 Weincloud 2023-07-26 N/A 7.5 HIGH
Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.