An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.
The product stores a password in plaintext within resources such as memory or files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Easyweb | Weintek | 2.1.53 (including) | 2.1.53 (including) |
| Cmt-3072xh2_firmware | Weintek | 20231011 (including) | 20231011 (including) |