Zurück zur Übersicht

MB connect line: Multiple Vulnerabilities in mbCONNECT24/mymbCONNECT24

VDE-2026-024
Last update
23.03.2026 13:00
Published at
23.03.2026 13:00
Vendor(s)
MB connect line GmbH
External ID
VDE-2026-024
CSAF Document

Summary

Multiple vulnerabilities have been discovered in MB connect line mbCONNECT24/mymbCONNECT24 that could allow unauthenticated RCE or SQLi.

Impact

CVE-2026-32968 allows unauthenticated RCE resulting in full system compromise impacting confidentiality, integrity, and availability, while CVE-2026-32969 allows unauthenticated SQLi resulting in arbitrary read access to the complete database.

Affected Product(s)

Model no. Product name Affected versions
MB connect line mbCONNECT24 Firmware 2.19.3, Firmware <=2.19.3
mymbCONNECT24 Firmware 2.19.3, Firmware <=2.19.3

Vulnerabilities

Expand / Collapse all

Published
23.03.2026 12:16
Weakness
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Summary

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

References

Published
23.03.2026 12:16
Weakness
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Summary

An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

References

Remediation

Update the mbCONNECT24/mymbCONNECT24 instance to version 2.19.4.

Acknowledgments

MB connect line GmbH thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 23.03.2026 13:00 Initial revision.