CVE-2023-0104: Weintek Easybuilder Pro
High severity, CVSS 7.8. EPSS: 21.8% chance of exploitation in the next 30 days.
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.
Affected products
- Weintek Easybuilder Pro: before 6.07.02.480 (fixed in 6.07.02.480); from 6.08.01.190, before 6.08.01.350 (fixed in 6.08.01.350)
Published 2023-02-22. Last modified 2026-06-17.