Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A security vulnerability in the device serial reset function allows a high-privileged user to perform unauthorized database queries. This could lead to the exposure of sensitive information stored within the platform's database, potentially compromising customer data or system configurations.
Technical details
A SQL injection vulnerability exists in the DevSerialReset function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The issue stems from improper neutralization of special elements within a SQL SELECT command. A remote attacker with high privileges can exploit this flaw to execute arbitrary SQL queries against the backend database. Successful exploitation results in a total loss of confidentiality for the data stored in the database. The vulnerability is reachable over the network without user interaction, though it requires administrative-level (high) privileges.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory