Executive brief
MB connect line remote access platforms are used for industrial communication and remote maintenance of machinery. A security flaw allows an unauthenticated attacker to access the underlying database, potentially leading to the theft of sensitive account information and configuration data. This could compromise the confidentiality of the industrial environment and its users.
Technical details
A SQL injection vulnerability exists in the getAccountData function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The root cause is the improper neutralization of special elements within a SQL SELECT command (CWE-89). An unauthenticated remote attacker can exploit this over the network without user interaction to execute arbitrary SQL queries. Successful exploitation allows the attacker to read sensitive data from the database, resulting in a total loss of confidentiality.
Affected products
- MB connect line GmbH mbCONNECT24 <= 2.20.0
- MB connect line GmbH mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: advisory: Advisory VDE-2026-044 published by CERT VDE
- 2026-05-27: disclosed: CVE-2026-40850 published to NVD