CVE-2023-50466: Weintek CMT2078X Firmware
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.
Affected products
- Weintek CMT2078X Firmware: version 2.1.3 only
Published 2023-12-19. Last modified 2026-06-17.