logo

Critical RCE and SQLi Flaws Shatter mbCONNECT24 Industrial Security

ID: 6e137490-66c8-59d6-b11c-0b61b6197e14

STIX ID: report--6e137490-66c8-59d6-b11c-0b61b6197e14

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

**CERT@VDE reports critical vulnerabilities in MB Connect Line's mbCONNECT24 and mymbCONNECT24 (<= firmware 2.19.4), including an unauthenticated RCE (generateSrpArray) and multiple unauthenticated SQL injections that allow full system compromise, arbitrary database read/write, and exposure of database credentials; administrators are urged to upgrade to patched firmware immediately.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.