Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote access platforms used for industrial communication and machine maintenance. A security vulnerability in the system's logging function allows a high-privileged user to perform unauthorized database operations. An attacker could exploit this to read sensitive information from the entire database or delete certain non-critical records, potentially compromising data confidentiality and system integrity.
Technical details
A SQL injection vulnerability exists in the DeleteSysLogEntry function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL DELETE command. While the vulnerability is described as unauthenticated in the function itself, the CVSS metrics indicate it requires high privileges (PR:H) to reach the attack vector. A successful exploit allows a remote attacker to perform unauthorized SELECT queries against the entire database and delete entries within non-critical tables. This results in a total loss of confidentiality and a partial loss of integrity.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory