Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote access and industrial monitoring, are affected by a security flaw that allows unauthorized access to their internal databases. An attacker can exploit this to steal sensitive information without needing a username or password. This could lead to a total loss of data confidentiality, potentially exposing industrial configurations or customer information.
Technical details
A SQL injection vulnerability exists in the '_mb24confi_getTagAlarm' function within the 'dataapi.php' file of MB connect line mbCONNECT24 and mymbCONNECT24. The issue stems from improper neutralization of special elements in a SQL SELECT command, allowing an unauthenticated remote attacker to execute arbitrary SQL queries via the network. Successful exploitation enables the attacker to read sensitive data from the database, resulting in a total loss of confidentiality. The vulnerability affects firmware versions up to and including 2.20.0. Users are advised to contact the vendor for patch information or upgrade to a secure version if available.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed: Initial advisory publication by CERT VDE
- 2026-05-27: advisory: NVD publication of CVE-2026-40814