August 24, 2026

HMI Security Flaw: What NJ Businesses Should Know

HMI Security Flaw: What NJ Businesses Should Know

A Low-Level User Can Become an Admin. That’s a Problem.

CISA flagged a serious vulnerability in the Weintek cMT3092X, a touchscreen HMI panel used in manufacturing and industrial environments. The short version: someone with basic, limited access to the panel’s web interface can manipulate cookies to give themselves full admin privileges. CVSS score is 8.8 out of 10. That’s not a minor issue.

If you run a production floor, a packaging line, or any kind of automated equipment that uses one of these panels, this is worth your attention this week, not next month.

What’s Actually Broken Here

The panel runs a web component called EasyWeb. Versions below 2.1.20, combined with firmware older than February 2021, have four separate problems. Cookies aren’t validated properly, so a logged-in user can edit them to claim admin rights. Passwords are stored in plaintext. File permissions on critical resources are set wrong. User management has its own separate flaw on top of all that.

Any one of those would be concerning. All four together in a device sitting on your network is a real exposure. And because the attack works over the network with no special conditions required, an attacker doesn’t need physical access to the panel to exploit it.

Who’s Actually at Risk

If you’re a manufacturer, a food processor, a packaging shop, or any operation using Weintek panels for machine control or monitoring, check your firmware version. Weintek has a patch available: cmt_typeB_20260316_007.patch, which includes EasyWeb 2.3.17. You have to request it directly from Weintek support or through your distributor. It’s not a standard firmware release they’re pushing automatically.

That last part matters. Nobody is going to push this to you. You have to go get it.

The Bigger Issue for Small and Mid-Size Operations

Most small manufacturers I’ve worked with in NJ don’t have a formal process for patching OT equipment. Windows servers get updates, laptops get updates, but the HMI panel on the production floor? It gets touched when something breaks. That’s understandable. Downtime is expensive and these systems are often running 24 hours.

But that also means vulnerabilities like this one sit unpatched for months or years. The firmware version this advisory covers is from 2021. There are panels out there that haven’t been updated since they were installed.

The other thing worth saying: HMI panels are increasingly connected. They’re on the same network as your business systems, sometimes accessible remotely for troubleshooting. That’s convenient, but it means a vulnerability on the production floor isn’t isolated from your accounting data or your Microsoft 365 environment.

What to Do Right Now

First, find out if you have any Weintek cMT3092X panels deployed. Check with whoever manages your production equipment or your automation vendor. If you do have them, check the firmware version and the EasyWeb version.

If you’re below firmware 20210218 or EasyWeb 2.1.20, contact Weintek support at weintek.com to request the patch. Their technical document TEC25003E has the full details.

While you’re waiting for the patch, limit network access to the panel. If it doesn’t need to be reachable from the internet, make sure it isn’t. Put it on a segmented VLAN if you can. Restrict which internal users can reach it at all.

This is also a good moment to do a quick inventory of other OT and IoT devices on your network. Printers, cameras, building controls, other HMI panels. Most of them have firmware that can be updated and most of them haven’t been.

A Concrete Takeaway

Patch the Weintek panel if you have one. Request the patch directly from Weintek, don’t wait for it to show up. And use this as a reason to build a basic process for reviewing OT device firmware at least once a year.

If you’re not sure what’s on your network or how exposed you are, Exine works with NJ manufacturers and businesses to get a clear picture of exactly that.

Tomasz Sobolewski, founder of Exine LLC
About the author
Tomasz Sobolewski
Founder of Exine LLC. Hands-on IT, cybersecurity and backup for growing New Jersey businesses, with 15+ years in the field. The kind of support that knows your systems and picks up the phone.