Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote access platforms used for industrial communication and machine monitoring. A vulnerability in the Easy View component allows a remote attacker with low-level access to perform unauthorized database queries. This could lead to a total loss of confidentiality, potentially exposing sensitive industrial configuration data or customer information.
Technical details
A SQL injection vulnerability exists in the Easy View component of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions 2.20.0 and earlier. The flaw stems from improper neutralization of special elements within SQL SELECT commands. A remote attacker with low-privileged credentials can exploit this over the network to execute arbitrary SQL queries against the backend database. Successful exploitation results in a total loss of confidentiality (C:H), allowing the attacker to read sensitive data. The vulnerability is tracked as CVE-2026-40831 and was disclosed alongside several other SQLi flaws in the same product suite.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed: Initial advisory published by CERT@VDE
- 2026-05-27: advisory: NVD record published