CVE-2026-60135 MEDIUM

CVE-2026-60135: Weintek cMT3092X Incorrect User Management

Vendor Weintek
Product cMT3092X firmware
Weakness CWE-286
Published July 24, 2026
Last update July 27, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

An attacker can modify data that should be restricted to read‑only access.

Key dates

02Disclosure timeline

July 24, 2026 CVE published
July 27, 2026 Record updated