Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote access platforms used for industrial communication and machine monitoring. A security vulnerability in the system_tag view allows an attacker with low-level access to perform unauthorized database queries. This could lead to a complete exposure of sensitive system data, potentially compromising industrial operations and confidential configuration information.
Technical details
A SQL injection vulnerability exists in the system_tag view of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to a total loss of confidentiality for the underlying database. Users are advised to update to a patched version if available.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory