CVE-2025-14750: Weintek Cmt-CTRL01

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. A low-privileged user can modify the parameters and potentially manipulate account-level privileges.

Affected products

  • Weintek Cmt-CTRL01: from 20230308, before 20250827 (fixed in 20250827)
  • Weintek Cmt-Svrx-820: from 20220413, before 20240919 (fixed in 20240919)
  • Weintek CMT3072XH: from 20200630, before 20241112 (fixed in 20241112)
  • Weintek CMT3072XHT: from 20200630, before 20241112 (fixed in 20241112)

Published 2026-01-22. Last modified 2026-06-17.