Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A vulnerability in the device serial reset function allows a high-privileged user to perform unauthorized database operations. This could lead to the exposure of sensitive system data and the modification of certain non-critical database records.
Technical details
A SQL injection vulnerability exists in the DevSerialReset function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL UPDATE command. While the attacker requires high privileges to reach the vulnerable component, a successful exploit allows for full database read access (confidentiality loss) and the ability to change values in non-critical tables (partial integrity loss). The vulnerability is reachable over the network without user interaction. Users are advised to contact the vendor for patch information or upgrade to a version beyond 2.20.0 if available.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: advisory: Initial advisory published by CERT VDE and NVD.