Executive brief
MB connect line mbCONNECT24 is a remote service platform used for industrial communication and remote maintenance. A security flaw allows an unauthenticated attacker to access the underlying database without a password. This could lead to a total loss of confidentiality, potentially exposing sensitive industrial configuration data or customer information.
Technical details
A SQL injection vulnerability exists in the mb24alarm.php file within the _mb24confi_getTagAlarm function of MB connect line mbCONNECT24 and mymbCONNECT24. The issue stems from improper neutralization of special elements in a SQL SELECT command. An unauthenticated remote attacker can exploit this over the network to execute arbitrary SQL queries. Successful exploitation allows the attacker to read sensitive information from the database, resulting in a total loss of confidentiality. The vulnerability is present in firmware versions up to and including 2.20.0.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory