CVE-2024-55019
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.
Published:Mar 3, 2026
Last Modified:Mar 4, 2026
EPS:Mar 3, 2026
EPSS Score:0.00038
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Weintek
Product
Cmt-3072xh2
Weintek
Cmt-3072xh2
Vendor
Weintek
Product
Cmt-3072xh2 Firmware
Weintek
Cmt-3072xh2 Firmware
Vendor
Weintek
Product
Cmt3072xh
Weintek
Cmt3072xh
Vendor
Weintek
Product
Easyweb
Weintek
Easyweb
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
