Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A security vulnerability in the data management component allows a high-privileged user to perform unauthorized database queries. This could lead to the exposure of sensitive information stored within the system's database, potentially compromising customer data or operational configurations.
Technical details
A SQL injection vulnerability exists in the 'dsgvo_contracts' view of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with high privileges can exploit this vulnerability over the network without user interaction to execute arbitrary SQL queries. Successful exploitation allows the attacker to read sensitive data from the underlying database, resulting in a total loss of confidentiality. Users are advised to update to a patched version as indicated by the vendor.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory