Executive brief
MB connect line industrial remote access platforms are vulnerable to a security flaw in their dashboard interface. A remote attacker with low-level user permissions can exploit this to gain unauthorized access to the entire underlying database. This could lead to a complete exposure of sensitive configuration data and system information.
Technical details
A SQL injection vulnerability exists in the dashboard view of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-level authenticated access can inject malicious SQL queries to bypass intended data restrictions. Successful exploitation allows the attacker to read arbitrary data from the database, resulting in a total loss of confidentiality. The vulnerability is reachable over the network without user interaction.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory