CVE-2023-43492: Weintek Cmt-Fhd Firmware
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
Affected products
- Weintek Cmt-Fhd Firmware: before 20210212 (fixed in 20210212)
- Weintek Cmt-Hdm Firmware: before 20210206 (fixed in 20210206)
- Weintek CMT3071 Firmware: before 20210220 (fixed in 20210220)
- Weintek CMT3072 Firmware: before 20210220 (fixed in 20210220)
- Weintek CMT3090 Firmware: before 20210220 (fixed in 20210220)
- Weintek CMT3103 Firmware: before 20210220 (fixed in 20210220)
- Weintek CMT3151 Firmware: before 20210220 (fixed in 20210220)
Published 2023-10-19. Last modified 2026-06-17.