Junglewise Threat Intelligence

CVE-2026-40851: MB connect line mbNET code execution in cfgparser via USB

CVE-2026-40851 · Severity: high · CVSS 8.4 · Published 2026-05-27

Vendors: MB connect line.

Executive brief

A vulnerability in MB connect line industrial routers allows an attacker with physical access to take full control of the device. By inserting a specially crafted USB stick, an attacker can exploit the configuration parser to execute unauthorized commands. This could lead to a complete compromise of the device, potentially disrupting industrial operations or exposing sensitive network data.

Technical details

A type confusion vulnerability (CWE-1287) exists in the 'cfgparser' component of MB connect line mbNET, mbNET.rokey, and mbNET.mini firmware. The issue stems from improper validation of input types when processing configuration files from external USB storage. A local attacker with physical access can trigger this vulnerability by inserting a USB stick containing a specially crafted file, leading to arbitrary code execution with high privileges. This results in a total loss of confidentiality, integrity, and availability. The vulnerability is addressed in mbNET/mbNET.rokey version 8.4.5 and mbNET.mini version 3.0.3.

Affected products

  • MB connect line mbNET.mini <= 3.0.2
  • MB connect line mbNET/mbNET.rokey <= 8.4.4

Timeline

  • 2026-05-27: advisory: Initial advisory published by CERT@VDE
  • 2026-05-27: patched: Fixes released in firmware versions 8.4.5 and 3.0.3

References

Related threats