CVE-2023-0104: Weintek Easybuilder Pro

High severity, CVSS 7.8. EPSS: 21.8% chance of exploitation in the next 30 days.

The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  

Affected products

  • Weintek Easybuilder Pro: before 6.07.02.480 (fixed in 6.07.02.480); from 6.08.01.190, before 6.08.01.350 (fixed in 6.08.01.350)

Published 2023-02-22. Last modified 2026-06-17.