CVE-2021-27444
Summary
| CVE | CVE-2021-27444 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-16 18:15:00 UTC |
| Updated | 2022-07-29 13:24:00 UTC |
| Description | The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Weintek | Cmt-ctrl01 | - | All | All | All |
| Operating System | Weintek | Cmt-ctrl01 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-fhd | - | All | All | All |
| Operating System | Weintek | Cmt-fhd Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-g01 | - | All | All | All |
| Operating System | Weintek | Cmt-g01 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-g02 | - | All | All | All |
| Operating System | Weintek | Cmt-g02 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-g03 | - | All | All | All |
| Operating System | Weintek | Cmt-g03 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-g04 | - | All | All | All |
| Operating System | Weintek | Cmt-g04 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-hdm | - | All | All | All |
| Operating System | Weintek | Cmt-hdm Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-svr-100 | - | All | All | All |
| Operating System | Weintek | Cmt-svr-100 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-svr-102 | - | All | All | All |
| Operating System | Weintek | Cmt-svr-102 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-svr-200 | - | All | All | All |
| Operating System | Weintek | Cmt-svr-200 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt-svr-202 | - | All | All | All |
| Operating System | Weintek | Cmt-svr-202 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt3071 | - | All | All | All |
| Operating System | Weintek | Cmt3071 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt3072 | - | All | All | All |
| Operating System | Weintek | Cmt3072 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt3090 | - | All | All | All |
| Operating System | Weintek | Cmt3090 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt3103 | - | All | All | All |
| Operating System | Weintek | Cmt3103 Firmware | All | All | All | All |
| Hardware | Weintek | Cmt3151 | - | All | All | All |
| Operating System | Weintek | Cmt3151 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| dl.weintek.com/public/Document/TEC/TEC21001E_cMT_EasyWeb_V1_Security_Issues.pdf | CONFIRM | dl.weintek.com | |
| Weintek EasyWeb cMT | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Marcin Dudek from CERT.PL reported these vulnerabilities to CISA.
There are currently no legacy QID mappings associated with this CVE.