All stories
highDefensive GuidanceCVE-2026-16002

Parsing errors in lib60870 library trigger denial of service on Weintek cMT3092X hardware

A high-severity vulnerability in the `lib60870` library can be used to crash parsing processes, leading to a denial of service. This affects Weintek cMT3092X hardware. Immediate attention is required for systems relying on this specific library version.

Summary

A critical flaw has been identified in the lib60870 library developed by MZ Automation. The vulnerability, tracked as CVE-2026-16002, stems from an out-of-bounds read error during data parsing. If triggered, this flaw allows an attacker to crash the parsing process, resulting in a denial of service (DoS) condition.

The impact of this vulnerability extends to the Weintek cMT3092X industrial control hardware. Because the flaw resides within a library used for protocol handling or data processing, an interruption to the parsing engine can halt critical industrial operations that depend on continuous data flow through the affected device.

Technical details

The core of the issue lies in how lib60870 handles specific memory read operations. An out-of-bounds read occurs when the software attempts to access a memory location outside the intended buffer range. In the context of industrial protocols, this often happens when a specially crafted packet is sent to the device, forcing the parser to look for data where none exists or beyond the allocated memory segment.

While the vulnerability allows for an out-of-bounds read, the primary consequence identified is the disruption of the parsing process itself. This crash prevents the system from processing subsequent legitimate commands or telemetry, effectively neutralizing the device's ability to communicate or function within its operational environment.

The CVSS score for this vulnerability is 8.2, reflecting a high level of severity. The attack vector is network-based (AV:N), meaning an attacker does not require physical access to the hardware to trigger the crash, provided they can reach the device over the network. The complexity of the attack is low (AC:L) and requires no specific user interaction (UI:N).

Why this matters for defenders

For operators managing Weintek cMT3092X hardware, a denial of service event can lead to immediate loss of visibility or control over industrial processes. If the parsing process crashes, any automated logic or monitoring systems relying on that data stream will fail.

Defenders should prioritize identifying all instances where lib60780 is utilized within their network architecture. Because this is a library-level vulnerability, it may be embedded in various software components or firmware versions used across different industrial platforms.

Defender guidance

Immediate steps should focus on network segmentation and traffic monitoring. Ensure that the Weintek cMT3092X devices are not exposed directly to untrusted networks. Restrict access to these devices to only known, authorized engineering workstations or control systems.

Monitor for unusual network behavior or unexpected restarts of industrial control services. Since the vulnerability is triggered by malformed data causing a crash, any sudden cessation of communication from a cMT3092X device should be investigated as a potential exploitation attempt or a critical system failure.

Check for available updates from MZ Automation or Weintek that specifically address the lib60870 library to remediate the out-of-bounds read vulnerability.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -