An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.
The vulnerability results from improper neutralization of special characters in the SQL UPDATE command executed by the setinfo endpoint. An attacker can craft a malicious HTTP request containing dangerous character sequences that will be embedded directly in the SQL query without proper sanitization. Since the endpoint does not require authentication, exploitation is possible for anyone with network access to the device.
An attacker can manipulate or destroy data in the database (loss of integrity) and cause system unavailability (loss of availability). According to the description, the vulnerability results in complete loss of integrity and availability.
Patches available from the manufacturer should be applied in accordance with references (https://certvde.com/de/advisories/VDE-2026-030). Until the fix is implemented, it is recommended to restrict network access to the setinfo endpoint through a firewall or network segmentation so that devices are not accessible from untrusted networks.
Mbconnectline Mbconnect24 and Mbconnectline Mymbconnect24 — specific versions indicated in the manufacturer's references (VDE-2026-030).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HMbconnectline Mbconnect24
APPMbconnectline≤ 2.19.4Mbconnectline Mymbconnect24
APPMbconnectline≤ 2.19.4
Related vulnerabilities
Brak domyślnej ochrony przed brute force w MB CONNECT LINE mymbCONNECT24
RCE bez uwierzytelnienia w MB CONNECT LINE mymbCONNECT24 i mbCONNECT24
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo e...
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an...
An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb2...