Executive brief
MB connect line industrial routers are used to provide secure remote access to industrial control systems. A vulnerability in the configuration management system allows an administrator-level attacker to inject malicious code into the device's settings. If exploited, this allows the attacker to take full control of the router, potentially disrupting industrial operations or accessing sensitive internal network traffic.
Technical details
An OS command injection vulnerability (CWE-78) exists in the configuration generator of MB connect line mbNET, mbNET.rokey, and mbNET.mini devices. A highly authenticated attacker can modify configuration parameters that are subsequently passed to a system execution call without adequate validation. This allows for the injection of arbitrary payloads into future generated configurations, resulting in remote code execution with high privileges. The attack is reachable over the network but requires high-level administrative credentials. Patches are available in firmware versions 8.4.5 for mbNET/mbNET.rokey and 3.0.3 for mbNET.mini.
Affected products
- MB connect line mbNET.mini <= 3.0.2
- MB connect line mbNET <= 8.4.4
- MB connect line mbNET.rokey <= 8.4.4
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
- 2026-05-27: patched: Fixed in mbNET/mbNET.rokey 8.4.5 and mbNET.mini 3.0.3