Junglewise Threat Intelligence

CVE-2026-40817: MB connect line mbCONNECT24 SQL injection in getAlarmProfiles

CVE-2026-40817 · Severity: high · CVSS 7.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line industrial communication platforms are affected by a security vulnerability that allows unauthorized access to internal data. By sending specially crafted requests to the device's alarm profile function, an attacker can bypass security controls to read sensitive information from the system's database. This could lead to the exposure of configuration details or other confidential operational data without requiring any login credentials.

Technical details

A SQL injection vulnerability exists in the getAlarmProfiles function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The root cause is the improper neutralization of special elements within a SQL SELECT command. An unauthenticated remote attacker can exploit this by sending malicious input to the affected endpoint, allowing them to execute arbitrary SQL queries. This results in a total loss of confidentiality as the attacker can extract data from the underlying database. The vulnerability is reachable over the network without user interaction or prior authentication.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: advisory: VDE-2026-044 published by CERT@VDE
  • 2026-05-27: disclosed: CVE-2026-40817 published to NVD

References

Related threats