← Vulnerability feed

Vulnerability record · CVE-2024-55020 · published 3 March 2026

CVE-2024-55020: Weintek easyweb improper input validation vulnerability

Weintek · Easyweb

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.

9.8 CVSS 3.1 Critical EPSS 1.7% · top 24.2% CWE-20 · Improper input validationCWE-78 · OS command injection
9.8CVSS 3.1 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-55020 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-55024Weintek easyweb vulnerabilityAn authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attack…EPSS 0.36%9.8CVE-2024-55026Weintek easyweb vulnerabilityAn issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary command…EPSS 0.34%8.8CVE-2024-55022Weintek easyweb code injection vulnerabilityWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name paramet…EPSS 1.3%7.5CVE-2024-55021Weintek easyweb hard-coded credentials vulnerabilityWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.EPSS 0.34%7.5CVE-2024-55027Weintek easyweb cleartext storage of sensitive data vulnerabilityWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.EPSS 0.22%7.5CVE-2024-55019Weintek easyweb improper access control vulnerabilityIncorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated att…EPSS 0.29%6.5CVE-2024-55025Weintek easyweb improper access control vulnerabilityIncorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI sy…EPSS 0.30%5.3CVE-2024-55023Weintek easyweb hard-coded credentials vulnerabilityWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitiv…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2024-55020), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.