CRITICAL🇵🇱 Wersja polska

CVE-2024-45275

CVSS 9.8v3.1pub. 2024-10-15upd. 2024-11-21

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

🤖 AI Analysis
How it works

Two user accounts with fixed, unchangeable passwords are embedded in the device firmware (CWE-798 — Use of Hard-coded Credentials). Since the authentication credentials are identical across all instances of a given model and cannot be changed by the administrator, an attacker who knows these passwords can log in to any vulnerable device without any additional authorization. The attack is possible remotely over the network, without requiring prior access or user interaction.

Impact

Attackers gain full control over the device, including the ability to read and modify configuration, disrupt device operation, and potentially use it as an entry point to a broader industrial network.

Mitigation & patch

Apply patches available from the manufacturer according to references (CERT VDE: VDE-2024-056 and VDE-2024-066). Additionally, it is recommended to isolate devices from the public Internet, restrict network access to these devices to trusted hosts only, and monitor login attempts.

Who is affected

Mbconnectline Mbnet.Mini (Firmware), Helmholz Rex 100 (Firmware) — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Helmholz Rex 100

    HW
    Helmholz
    all versions
  • Helmholz Rex 100 Firmware

    OS
    Helmholz
    < 2.3.1
  • Mbconnectline Mbnet.mini

    HW
    Mbconnectline
    all versions
  • Mbconnectline Mbnet.mini Firmware

    OS
    Mbconnectline
    < 2.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-45274CRITICAL9.8PL ✓same product

Zdalne wykonanie poleceń OS bez uwierzytelnienia via UDP w urządzeniach Mbconnectline i Helmholz

CVE-2025-41675HIGH7.2same product

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server c...

CVE-2025-41674HIGH7.2same product

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic ac...

CVE-2025-41673HIGH7.2same product

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms acti...

CVE-2024-45276HIGH7.5same product

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authent...