Junglewise Threat Intelligence

CVE-2026-40845: MB connect line mbCONNECT24 SQL injection in devices_configuration view

CVE-2026-40845 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line GmbH mymbCONNECT24, MB connect line GmbH mbCONNECT24.

Executive brief

A vulnerability exists in MB connect line's remote access platforms, which are used to manage industrial routers and IoT devices. An attacker with low-level user permissions can exploit a flaw in how the system handles database queries to gain unauthorized access to sensitive information. This could lead to a complete exposure of confidential data stored within the management platform.

Technical details

A SQL injection vulnerability exists in the 'devices_configuration' view of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can exploit this vulnerability via the network without user interaction. Successful exploitation allows the attacker to perform unauthorized database queries, potentially leading to a total loss of confidentiality for all data stored in the affected database.

Affected products

  • MB connect line GmbH mbCONNECT24 <=2.20.0
  • MB connect line GmbH mymbCONNECT24 <=2.20.0

Timeline

  • 2026-05-27: advisory: Advisory VDE-2026-044 published by CERT VDE
  • 2026-05-27: disclosed: CVE-2026-40845 published to NVD dataset

References