Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Weintek

First CVE: May 16, 2022Active for: 4 yearsTotal CVEs: 22
37.9
VTI Score
Medium

Weintek develops human-machine interface (HMI) and industrial control software, particularly embedded display terminals and web-based engineering platforms used in manufacturing and process automation. The vendor's vulnerability portfolio spans a focused product line centered on its cMT touchscreen series and EasyWeb configuration tools, which sit in operational-technology environments where patching cycles are often slow and device lifespans extend across years. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, driven by recurrent weakness classes including OS command injection, hard-coded credentials, improper access control, and code injection—flaws that reflect the low-level system access and remote-configuration capabilities embedded in HMI software and that create direct paths to supervisory control in industrial networks. Defenders deploying Weintek HMI devices should prioritize inventory and network segmentation, as these devices frequently operate in environments with limited compensating controls and irregular update practices. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Weintek over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2022
4 years ago
Most Recent CVE
Mar 3, 2026
143 days ago

Products(39 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0104HIGH
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of th
Feb 22, 20237.835NONO
CVE-2023-5777CRITICAL
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is expos
Nov 6, 20239.832NONO
CVE-2024-55026CRITICAL
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET r
Mar 3, 20269.831NONO
CVE-2024-55024CRITICAL
An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative a
Mar 3, 20269.831NONO
CVE-2024-55020CRITICAL
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands wit
Mar 3, 20269.831NONO
CVE-2021-27446CRITICAL
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
May 16, 20229.830NONO
CVE-2024-55022HIGH
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.
Mar 3, 20268.829NONO
CVE-2021-27444CRITICAL
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information an
May 16, 20229.829NONO
CVE-2023-43492CRITICAL
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and
Oct 19, 20239.826NONO
CVE-2023-38584CRITICAL
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow an
Oct 19, 20239.826NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
18%
45%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High1 (4.5%)
Unknown0 (0.0%)
User Interaction
None20 (90.9%)
Unknown0 (0.0%)
Required2 (9.1%)
Privileges Required
Low4 (18.2%)
High0 (0.0%)
None18 (81.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Weintek.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Weintek — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Weintek's Products

View all 2 CNAs →

Top CWEs