Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A vulnerability in the administrative interface allows a high-privileged user to perform unauthorized database operations. This could lead to the exposure of sensitive system data and the modification of certain non-critical database records.
Technical details
A SQL injection vulnerability exists in the UpdateParam function within the admin.mbnetj.php file of MB connect line mbCONNECT24 and mymbCONNECT24. The issue stems from improper neutralization of special elements within a SQL UPDATE command. A remote attacker with high privileges can exploit this flaw via the network without user interaction. Successful exploitation allows the attacker to read the entire database (total loss of confidentiality) and modify values in non-critical tables (partial loss of integrity). The vulnerability is addressed in versions newer than 2.20.0.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: advisory: Advisory published by CERT VDE and NVD