Junglewise Threat Intelligence

CVE-2026-40829: MB connect line mbCONNECT24 SQL injection in UpdateParam

CVE-2026-40829 · Severity: medium · CVSS 5.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A security vulnerability in these platforms allows a high-privileged user to perform unauthorized database operations. This could lead to the exposure of sensitive information across the entire database and the modification of certain non-critical data.

Technical details

A SQL injection vulnerability exists in the UpdateParam function within the view.html.php file of MB connect line mbCONNECT24 and mymbCONNECT24 (firmware versions <= 2.20.0). The flaw stems from improper neutralization of special elements in a SQL UPDATE command. A remote attacker with high privileges can exploit this over the network to execute arbitrary SQL queries. Successful exploitation allows the attacker to read the entire database (total loss of confidentiality) and modify values in non-critical tables (partial loss of integrity). The vulnerability is tracked as CVE-2026-40829 and was disclosed alongside several other SQL injection flaws in the same product suite.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Initial advisory publication by CERT VDE
  • 2026-05-27: advisory: NVD record published

References

Related threats