Back to search
CVE-2025-14750
Published: Jan 22, 2026
Modified: Jan 26, 2026
PUBLISHED
Description
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. A low-privileged user can modify the parameters and potentially manipulate account-level privileges.
| Vendor | Product | Versions |
|---|---|---|
Weintek | cMT3072XH | affected 20200630 - < 20241112 |
Weintek | cMT3072XH(T) | affected 20200630 - < 20241112 |
Weintek | cMT-SVRX-820 | affected 20220413 - < 20240919 |
Weintek | cMT-CTRL01 | affected 20230308 - < 20250827 |
Weaknesses (CWE)
References
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-05
government-resource
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now