Junglewise Threat Intelligence

CVE-2026-10521: MB connect line mbCONNECT24 forced browsing in configuration settings

CVE-2026-10521 · Severity: high · CVSS 7.2 · Published 2026-06-23

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote maintenance and industrial data communication, contain a security flaw that allows high-privileged users to access restricted settings. An attacker with administrative credentials can bypass intended interface restrictions to modify critical system parameters. This could lead to a complete loss of control over the device, potentially disrupting industrial operations or exposing sensitive configuration data.

Technical details

A forced browsing vulnerability (CWE-425) exists in MB connect line mbCONNECT24 and mymbCONNECT24 versions prior to 2.20.2. The flaw allows a remote attacker with high privileges to access a hidden configuration method that is not intended to be accessible by any user role. By directly requesting specific URLs or methods, the attacker can modify critical program parameters. Successful exploitation can result in a total compromise of the system's confidentiality, integrity, and availability. The issue is resolved in firmware version 2.20.2.

Affected products

  • MB connect line mbCONNECT24 < 2.20.2
  • MB connect line mymbCONNECT24 < 2.20.2

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory

References

Related threats