Executive brief
MB connect line industrial communication platforms are affected by a security flaw that allows users with low-level access to manipulate the underlying database. An attacker could exploit this to view sensitive information across the entire system or insert unauthorized data into certain tables. This could lead to a significant breach of data confidentiality and minor disruptions to system integrity.
Technical details
A SQL injection vulnerability exists in the saveDashboardLayout function within dash.php of MB connect line mbCONNECT24 and mymbCONNECT24. The issue stems from improper neutralization of special elements within a SQL INSERT command. A remote attacker with low-privileged credentials can exploit this flaw to perform unauthorized database queries, potentially leading to full disclosure of database contents and the ability to insert records into non-critical tables. The vulnerability is reachable over the network and affects firmware versions up to and including 2.20.0.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: advisory: VDE-2026-044 published by CERT VDE
- 2026-05-27: disclosed: CVE-2026-40833 published to NVD