CVE-2026-61886: Weintek CMT3092X Firmware

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Weintek cMT3092X HMI stores user account passwords in plaintext.

Affected products

  • Weintek CMT3092X Firmware: before 20210218 (fixed in 20210218)
  • Weintek Easyweb: before v2.1.20 (fixed in v2.1.20)

Published 2026-07-24. Last modified 2026-07-30.