Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote maintenance and industrial communication, are affected by a security vulnerability. A high-privileged remote attacker can exploit this flaw to read the entire database and delete certain non-critical records. This could lead to a significant exposure of sensitive configuration or operational data and minor disruptions to system integrity.
Technical details
A SQL injection vulnerability exists in the _RemoveRequest function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL DELETE command. A remote attacker with high privileges can exploit this to perform unauthorized database queries, potentially reading the entire database contents or deleting entries in non-critical tables. The attack is reachable over the network and does not require user interaction, though it does require high-level administrative credentials.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory