CRITICAL🇵🇱 Wersja polska

CVE-2026-33615

CVSS 9.1v3.1pub. 2026-04-02upd. 2026-04-16

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of special characters in the SQL UPDATE command executed by the setinfo endpoint. An attacker can craft a malicious HTTP request containing dangerous character sequences that will be embedded directly in the SQL query without proper sanitization. Since the endpoint does not require authentication, exploitation is possible for anyone with network access to the device.

Impact

An attacker can manipulate or destroy data in the database (loss of integrity) and cause system unavailability (loss of availability). According to the description, the vulnerability results in complete loss of integrity and availability.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with references (https://certvde.com/de/advisories/VDE-2026-030). Until the fix is implemented, it is recommended to restrict network access to the setinfo endpoint through a firewall or network segmentation so that devices are not accessible from untrusted networks.

Who is affected

Mbconnectline Mbconnect24 and Mbconnectline Mymbconnect24 — specific versions indicated in the manufacturer's references (VDE-2026-030).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Mbconnectline Mbconnect24

    APP
    Mbconnectline
    ≤ 2.19.4
  • Mbconnectline Mymbconnect24

    APP
    Mbconnectline
    ≤ 2.19.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2020-35565CRITICAL9.8PL ✓same product

Brak domyślnej ochrony przed brute force w MB CONNECT LINE mymbCONNECT24

CVE-2020-10383CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w MB CONNECT LINE mymbCONNECT24 i mbCONNECT24

CVE-2026-33614HIGH7.5same product

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo e...

CVE-2026-33613HIGH7.2same product

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an...

CVE-2026-33616HIGH7.5same product

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb2...