PatchSiren cyber security CVE debrief
CVE-2025-14751 Weintek CVE debrief
CISA’s CSAF advisory for CVE-2025-14751 describes an authentication bypass in Weintek cMT X Series HMI EasyWeb Service. A low-privileged user can bypass account credentials without confirming the user’s current authentication state, which may lead to unauthorized privilege escalation. The advisory lists affected models including cMT3072XH, cMT3072XH(T), cMT-SVRX-820, and cMT-CTRL01, and provides vendor-fixed versions for remediation. The supplied CVSS v3.1 vector is network-accessible and high severity.
- Vendor
- Weintek
- Product
- cMT3072XH
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-22
- Original CVE updated
- 2026-01-22
- Advisory published
- 2026-01-22
- Advisory updated
- 2026-01-22
Who should care
Industrial control system operators, OT administrators, plant engineers, and security teams managing Weintek cMT X Series HMIs or related EasyWeb deployments should prioritize this issue, especially where management interfaces are reachable from broader networks or shared administrative segments.
Technical summary
The vulnerability is an authentication-state bypass in the EasyWeb Service on affected Weintek devices. According to the advisory, a low-privileged user can bypass account credentials without confirming the current authentication state, enabling unauthorized privilege escalation. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L, indicating network accessibility, low attack complexity, and meaningful confidentiality and integrity impact. Affected products in the advisory are cMT3072XH, cMT3072XH(T), cMT-SVRX-820, and cMT-CTRL01.
Defensive priority
High. This is a network-reachable authentication flaw in an OT/HMI service with potential privilege escalation, so affected environments should patch quickly and limit exposure until remediation is complete.
Recommended defensive actions
- Upgrade affected devices to the vendor-fixed versions listed in the advisory: cMT3072XH and cMT3072XH(T) to 20241112, cMT-SVRX-820 to 20240919, and cMT-CTRL01 to 20250827.
- Restrict EasyWeb Service access to trusted management networks only; avoid direct exposure to untrusted or internet-reachable networks.
- Review privileged accounts, role assignments, and recent access logs for unexpected changes or suspicious authentication activity.
- Apply compensating controls if patching is delayed, such as network segmentation, firewall restrictions, and tighter administrative access paths.
- Confirm the affected device inventory includes all Weintek cMT X Series systems that may share the same service or management workflow.
Evidence notes
This debrief is based on CISA’s CSAF advisory ICSA-26-022-05 (published 2026-01-22T07:00:00Z), which names the affected Weintek products and the vendor-fixed versions. The advisory text states that a low-privileged user can bypass account credentials without confirming the user’s current authentication state, leading to unauthorized privilege escalation. The supplied advisory metadata also includes the CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L. No KEV listing was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14751 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14751
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14751 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14751
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-022-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.