Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A security vulnerability in the device management component allows a high-privileged user to execute unauthorized database commands. This could lead to the exposure of all stored database information and the unauthorized modification of certain non-critical system records.
Technical details
A SQL injection vulnerability (CWE-89) exists in the 'devices' parameter of the 'accountstatus' view within MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The root cause is improper neutralization of special elements within a SQL UPDATE command. While the vulnerability requires high-privileged authentication, a successful exploit allows a remote attacker to perform arbitrary SELECT queries to read the entire database and execute UPDATE commands on non-critical tables. This results in a total loss of confidentiality and a partial loss of integrity. Users are advised to update to a patched version if available.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed: Initial advisory publication by CERT VDE
- 2026-05-27: advisory: NVD publication of CVE-2026-40825