An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb24sysapi module.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMbconnectline Mbconnect24
APPMbconnectline≤ 2.5.0Mbconnectline Mymbconnect24
APPMbconnectline≤ 2.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2026-33615CRITICAL9.1PL ✓same product
SQL Injection w endpoincie setinfo produktów Mbconnectline
CVE-2020-35565CRITICAL9.8PL ✓same product
Brak domyślnej ochrony przed brute force w MB CONNECT LINE mymbCONNECT24
CVE-2026-33613HIGH7.2same product
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an...
CVE-2026-33614HIGH7.5same product
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo e...
CVE-2026-33616HIGH7.5same product
An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb2...