Executive brief
MB connect line mbCONNECT24 is a remote service platform used for industrial communication and remote maintenance of machinery. A security vulnerability allows an unauthenticated attacker to access the underlying database, potentially leading to the theft of sensitive industrial data or configuration information. This could compromise the confidentiality of customer operations and machine data managed through the platform.
Technical details
A SQL injection vulnerability exists in MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is located in the 'tagid' parameter of the 'getLiveValues' function due to improper neutralization of special elements in a SQL SELECT command. An unauthenticated remote attacker can exploit this by sending specially crafted network requests to the affected service. Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to a total loss of confidentiality of the database contents. The vulnerability is tracked as CVE-2026-40813 and was disclosed alongside several other SQL injection flaws in the same product.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed: Initial advisory publication by CERT@VDE
- 2026-05-27: advisory: NVD publication date