Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24, which are platforms used for remote access and management of industrial systems, are affected by a security vulnerability. A high-privileged remote attacker can exploit this flaw to gain unauthorized access to the underlying database. This could lead to a total loss of confidentiality for sensitive account information and operational data stored within the system.
Technical details
A SQL injection vulnerability exists in the getAccountByID function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The issue stems from improper neutralization of special elements within a SQL SELECT command. While the vulnerability is described as 'unauthenticated' in the summary text, the CVSS metrics and description specify that a high-privileged remote attacker is required to trigger the exploit. Successful exploitation allows an attacker to execute arbitrary SQL queries against the database, potentially resulting in the extraction of all stored data.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory