Junglewise Threat Intelligence

CVE-2026-40818: MB connect line mbCONNECT24 SQL injection in _mb24confi_getDevice

CVE-2026-40818 · Severity: high · CVSS 7.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote maintenance and industrial communication, are affected by a security vulnerability. An unauthenticated remote attacker can exploit this flaw to gain unauthorized access to the underlying database. This could lead to a total loss of confidentiality for sensitive operational data and device configurations.

Technical details

An unauthenticated SQL injection vulnerability exists in the _mb24confi_getDevice function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The root cause is the improper neutralization of special elements within a SQL SELECT command. A remote, unauthenticated attacker can exploit this over the network without any user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries, potentially leading to the extraction of sensitive information from the database. Users are advised to contact the vendor for patching information as multiple related SQLi vulnerabilities were disclosed in the same advisory.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Initial advisory publication by CERT VDE
  • 2026-05-27: advisory: NVD publication date

References

Related threats