Executive brief
MB connect line's remote access platforms, used for industrial communication and machine maintenance, contain a security flaw that allows unauthorized users to access the underlying database. By exploiting this vulnerability, an attacker could steal sensitive configuration data or customer information without needing a password. This could lead to a significant breach of confidentiality and potentially expose details about connected industrial equipment.
Technical details
A SQL injection vulnerability exists in the 'getLiveValues' function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The root cause is the improper neutralization of special elements within the 'sn' parameter before it is used in a SQL SELECT command. An unauthenticated remote attacker can exploit this by sending specially crafted network requests to the affected component. Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to a total loss of confidentiality of the database contents. The vulnerability was disclosed by CERT VDE.
Affected products
- MB connect line mbCONNECT24 <=2.20.0
- MB connect line mymbCONNECT24 <=2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory