CVE-2025-14750: Weintek Cmt-CTRL01
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. A low-privileged user can modify the parameters and potentially manipulate account-level privileges.
Affected products
- Weintek Cmt-CTRL01: from 20230308, before 20250827 (fixed in 20250827)
- Weintek Cmt-Svrx-820: from 20220413, before 20240919 (fixed in 20240919)
- Weintek CMT3072XH: from 20200630, before 20241112 (fixed in 20241112)
- Weintek CMT3072XHT: from 20200630, before 20241112 (fixed in 20241112)
Published 2026-01-22. Last modified 2026-06-17.