Junglewise Threat Intelligence

CVE-2026-40849: MB connect line mbCONNECT24 SQL injection in user_alarmprofile view

CVE-2026-40849 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line's remote access platforms, used for industrial communication and IoT connectivity, contain a security flaw in how they handle database queries. A remote attacker with low-level user permissions can exploit this to gain unauthorized access to sensitive information stored in the system's database. This could lead to a total loss of data confidentiality, potentially exposing configuration details or operational data.

Technical details

A SQL injection vulnerability exists in the user_alarmprofile view of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low privileges can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to a total loss of confidentiality for the data stored within the affected database.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: advisory: Advisory VDE-2026-044 published by CERT@VDE
  • 2026-05-27: disclosed: CVE-2026-40849 published to NVD

References

Related threats