CVE-2026-40851

8.4

MB connect line, Helmholz · mbNET, mbNET.rokey, mbNET.mini, REX200/250, REX100

A local input validation vulnerability in the cfgparser component allows a local attacker to achieve code execution via a maliciously crafted file on a USB device.

Executive summary

A critical input validation flaw in multiple MB connect line and Helmholz industrial gateway products permits local code execution via crafted USB storage.

Vulnerability

This is an improper validation of input (CWE-1287) vulnerability within the cfgparser. The vulnerability allows an attacker with local physical access to trigger a confusion attack using a specially crafted file on a USB stick.

Business impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the affected service. Given the CVSS score of 8.4, this poses a high risk to operational technology (OT) environments, potentially leading to unauthorized system control, loss of process integrity, or complete device compromise.

Remediation

Immediate Action: Update the affected devices to the latest firmware versions provided by the respective vendors (MB connect line or Helmholz) as detailed in the official security advisory (VDE-2026-054).

Proactive Monitoring: Restrict physical access to USB ports on industrial hardware and monitor logs for unexpected configuration parsing errors or unauthorized file system operations.

Compensating Controls: Disable USB functionality at the kernel or hardware level if the feature is not required for operational tasks to prevent the use of malicious storage media.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the severity of this code execution flaw, users should prioritize firmware updates for all listed industrial gateway devices. Physical security controls should be audited to ensure that unauthorized personnel cannot interact with device USB ports.