CRITICAL · 9.8

CVE-2021-27444

The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administra...

Vulnerability Description

The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
WeintekCmt-Svr-100 Firmware< 20210305
WeintekCmt-Svr-100-
WeintekCmt-Svr-102 Firmware< 20210305
WeintekCmt-Svr-102-
WeintekCmt-Svr-200 Firmware< 20210305
WeintekCmt-Svr-200-
WeintekCmt-Svr-202 Firmware< 20210305
WeintekCmt-Svr-202-
WeintekCmt-G01 Firmware< 20210209
WeintekCmt-G01-
WeintekCmt-G02 Firmware< 20210209
WeintekCmt-G02-
WeintekCmt-G03 Firmware< 20210222
WeintekCmt-G03-
WeintekCmt-G04 Firmware< 20210222
WeintekCmt-G04-
WeintekCmt3071 Firmware< 20210218
WeintekCmt3071-
WeintekCmt3072 Firmware< 20210218
WeintekCmt3072-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27444?

CVE-2021-27444 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administra...

How severe is CVE-2021-27444?

CVE-2021-27444 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-27444?

Check the references section above for vendor advisories and patch information. Affected products include: Weintek Cmt-Svr-100 Firmware, Weintek Cmt-Svr-100, Weintek Cmt-Svr-102 Firmware, Weintek Cmt-Svr-102, Weintek Cmt-Svr-200 Firmware.