Back to overview

MB connect line: Multiple Vulnerabilities in mbNET.mini Product

VDE-2024-056
Last update
08/27/2025 12:00
Published at
10/15/2024 10:00
Vendor(s)
MB connect line GmbH
External ID
VDE-2024-056
CSAF Document

Summary

Multiple vulnerabilities have been discovered in MB connect line mbNET.mini product allowing for RCE or unauthorized file access.

Impact

CVE-2024-45271, CVE-2024-45274 and CVE-2024-45275 allow remote code execution with system privileges, resulting in full compromise of the device.

CVE-2024-45273 allows undetectable tampering and manipulation of encrypted configuration files.

CVE-2024-45276 allows unauthenticated access to potential sensitive files.

Affected Product(s)

Model no. Product name Affected versions
MB connect line mbNET.mini Firmware <=2.2.13

Vulnerabilities

Expand / Collapse all

Published
09/22/2025 14:57
Weakness
Use of Hard-coded Credentials (CWE-798)
Summary

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

References

Published
09/22/2025 14:57
Weakness
Missing Authentication for Critical Function (CWE-306)
Summary

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

References

Published
09/22/2025 14:57
Weakness
Weak Encoding for Password (CWE-261)
Summary

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

References

Published
09/22/2025 14:57
Weakness
Improper Control of Generation of Code ('Code Injection') (CWE-94)
Summary

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

References

Published
09/22/2025 14:57
Weakness
Files or Directories Accessible to External Parties (CWE-552)
Summary

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

References

Remediation

Update mbNET.mini to the version 2.3.1

Revision History

Version Date Summary
1.0.0 10/15/2024 10:00 Initial revision.
1.0.1 11/06/2024 12:27 Fix: correct certvde domain, added self-reference
1.0.2 05/14/2025 14:28 Fix: version space
1.1.2 08/27/2025 12:00 Update: CWE from CVE-2024-45271, Revision History