CVE-2021-27444
high-risk
Published 2022-05-16
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.
Do I need to act?
-
0.30% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (16)
Cmt-Svr-100 Firmware
Cmt-Svr-102 Firmware
Cmt-Svr-200 Firmware
Cmt-Svr-202 Firmware
Cmt-G01 Firmware
Cmt-G02 Firmware
Cmt-G03 Firmware
Cmt-G04 Firmware
Cmt3071 Firmware
Cmt3072 Firmware
Cmt3090 Firmware
Cmt3103 Firmware
Cmt3151 Firmware
Cmt-Hdm Firmware
Cmt-Fhd Firmware
Cmt-Ctrl01 Firmware
Affected Vendors
References (4)
Third Party Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-21-082-01
Third Party Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-21-082-01
51
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
1/34 · Minimal
Exposure
18/34 · Moderate