Executive brief
MB connect line's remote access platforms, used for industrial communication and machine maintenance, contain a security flaw in their user information endpoint. An unauthenticated attacker can exploit this to access sensitive information stored in the system's database. This could lead to a total loss of confidentiality regarding user data and system configurations.
Technical details
A SQL injection vulnerability exists in the 'userinfo' endpoint of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to the affected endpoint. Successful exploitation allows the attacker to execute arbitrary SQL queries, potentially leading to the unauthorized extraction of sensitive data from the backend database.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory