Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mbconnect24 HIGH 7.5
CVE-2026-33616

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutraliz…

Fix: after 2.19.4
Fix from $1,950 2026-04-02
Mbconnect24 MEDIUM 5.3
CVE-2026-33617

An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality…

Fix: after 2.19.4
Fix from $1,600 2026-04-02
Mbconnect24 CRITICAL 9.1
CVE-2026-33615

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization …

Fix: after 2.19.4
Fix from $2,300 2026-04-02
Mbconnect24 HIGH 7.5
CVE-2026-33614

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization …

Fix: after 2.19.4
Fix from $1,950 2026-04-02
Mbconnect24 HIGH 8.8
CVE-2026-33613

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpAr…

Fix: after 2.19.4
Fix from $1,950 2026-04-02
Mbnet.mini Firmware HIGH 7.5
CVE-2025-41679

An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the netw…

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware HIGH 7.2
CVE-2025-41674

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of …

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware HIGH 7.2
CVE-2025-41675

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neu…

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware HIGH 7.2
CVE-2025-41678

A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a…

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware HIGH 7.2
CVE-2025-41673

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of sp…

Fix: 2.3.3+
Fix from $1,950 2025-07-21
Mbnet.mini Firmware CRITICAL 9.8
CVE-2024-45274

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

Fix: 2.3.1+
Fix from $2,300 2024-10-15
Mbnet.mini Firmware CRITICAL 9.8
CVE-2024-45275

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affec…

Fix: 2.3.1+
Fix from $2,300 2024-10-15
Mbnet.mini Firmware HIGH 7.5
CVE-2024-45276

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

Fix: 2.3.1+
Fix from $1,950 2024-10-15
Mbnet.mini Firmware HIGH 7.8
CVE-2024-45271

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

Fix: 2.3.1+
Fix from $1,950 2024-10-15
Mbnet.mini Firmware HIGH 7.8
CVE-2024-45273

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encrypt…

Fix: 2.3.1 / 2.16.3+
Fix from $1,950 2024-10-15
Mbconnect24 HIGH 8.8
CVE-2023-0985

An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2…

Fix: after 2.13.3
Fix from $1,950 2023-06-06
Mbconnect24 MEDIUM 5.3
CVE-2022-22520

A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNE…

Fix: after 2.11.2
Fix from $1,600 2022-09-14
Mbconnect24 HIGH 7.5
CVE-2021-34580

In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends f…

Fix: after 2.9.0
Fix from $1,950 2021-10-27
Mbdialup CRITICAL 9.8
CVE-2021-33527

In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORI…

Fix: after 3.9r0.0
Fix from $2,300 2021-08-02
Mbdialup HIGH 7.8
CVE-2021-33526

In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM in…

Fix: after 3.9r0.0
Fix from $1,950 2021-08-02
Mbconnect24 HIGH 7.5
CVE-2021-34575

In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of respons…

Fix: after 2.8.0
Fix from $1,950 2021-08-02
Mbconnect24 HIGH 7.7
CVE-2020-12528

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation a…

Fix: after 2.6.2
Fix from $1,950 2021-03-02
Mbconnect24 MEDIUM 6.5
CVE-2020-12527

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Impro…

Fix: after 2.11.2
Fix from $1,600 2021-03-02
Mbconnect24 MEDIUM 6.1
CVE-2020-12530

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redire…

Fix: after 2.6.2
Fix from $1,600 2021-03-02
Mbconnect24 MEDIUM 5.3
CVE-2020-12529

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access c…

Fix: after 2.6.2
Fix from $1,600 2021-03-02
Mbconnect24 CRITICAL 9.8
CVE-2020-35565

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.

Fix: after 2.6.2
Fix from $2,300 2021-02-16
Mbconnect24 HIGH 7.8
CVE-2020-35567

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but …

Fix: after 2.6.2
Fix from $1,950 2021-02-16
Mbconnect24 HIGH 7.5
CVE-2020-35558

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in th…

Fix: after 2.11.2
Fix from $1,950 2021-02-16
Mbconnect24 HIGH 7.5
CVE-2020-35564

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malici…

Fix: after 2.6.2
Fix from $1,950 2021-02-16
Mbconnect24 MEDIUM 6.5
CVE-2020-35557

An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in us…

Fix: after 2.11.2
Fix from $1,600 2021-02-16