The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Two user accounts with fixed, unchangeable passwords are embedded in the device firmware (CWE-798 — Use of Hard-coded Credentials). Since the authentication credentials are identical across all instances of a given model and cannot be changed by the administrator, an attacker who knows these passwords can log in to any vulnerable device without any additional authorization. The attack is possible remotely over the network, without requiring prior access or user interaction.
Attackers gain full control over the device, including the ability to read and modify configuration, disrupt device operation, and potentially use it as an entry point to a broader industrial network.
Apply patches available from the manufacturer according to references (CERT VDE: VDE-2024-056 and VDE-2024-066). Additionally, it is recommended to isolate devices from the public Internet, restrict network access to these devices to trusted hosts only, and monitor login attempts.
Mbconnectline Mbnet.Mini (Firmware), Helmholz Rex 100 (Firmware) — specific versions indicated in manufacturer references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHelmholz Rex 100
HWHelmholzall versionsHelmholz Rex 100 Firmware
OSHelmholz< 2.3.1Mbconnectline Mbnet.mini
HWMbconnectlineall versionsMbconnectline Mbnet.mini Firmware
OSMbconnectline< 2.3.1
Related vulnerabilities
Zdalne wykonanie poleceń OS bez uwierzytelnienia via UDP w urządzeniach Mbconnectline i Helmholz
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server c...
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic ac...
A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms acti...
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authent...