CVE-2026-33614

7.5

MB connect line · mbCONNECT24 and mymbCONNECT24

An unauthenticated SQL injection vulnerability in the getinfo endpoint of MB connect line products allows remote attackers to compromise system confidentiality via improper input neutralization.

Executive summary

An unauthenticated SQL injection vulnerability in MB connect line mbCONNECT24 and mymbCONNECT24 products poses a critical risk of total data confidentiality loss to affected systems.

Vulnerability

This is a SQL injection vulnerability (CWE-89) occurring within the getinfo endpoint. An unauthenticated remote attacker can inject malicious SQL commands into the application to extract sensitive data from the backend database.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a high severity due to the ease of exploitation and the potential for complete loss of confidentiality. Successful exploitation could lead to unauthorized access to sensitive operational data, regulatory non-compliance, and significant reputational damage to the organization relying on these industrial connectivity solutions.

Remediation

Immediate Action: Organizations should review the vendor advisory at certvde.com for specific patching instructions and apply available updates immediately. If a patch is not yet available for a specific deployment, restrict network access to the affected getinfo endpoint.

Proactive Monitoring: Security teams should implement database query logging and monitor for anomalous SQL syntax or unexpected high-volume data requests originating from the getinfo endpoint.

Compensating Controls: Deploy a Web Application Firewall (WAF) with custom rules designed to inspect and filter SQL injection patterns directed at the affected endpoint.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the potential for total loss of confidentiality, this vulnerability should be treated as a priority for remediation. Administrators must identify all instances of mbCONNECT24 and mymbCONNECT24 within their network and apply the necessary security updates as soon as they are provided by the vendor to prevent unauthorized data exfiltration.

Sources

Originally found and disclosed by Moritz Abrell, Christian Zäske from SySS GmbH, per the CVE Program record.