MB Connect Line mbNET.mini是德国MB Connect Line公司的一款远程接入路由器。 MB Connect Line mbNET.mini 2.3.3之前版本存在操作系统命令注入漏洞,该漏洞源于对OS命令中特殊元素中和不当,可能导致执行任意系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MB connect line | mbNET.mini | 0.0.0 ~ 2.3.3 | - |
|
| Helmholz | REX 100 | 0.0.0 ~ 2.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-41673 | 7.2 HIGH | Remote Command Injection in send_sms Action Due to Improper Input Neutralization |
| CVE-2025-41674 | 7.2 HIGH | Remote Command Injection in diagnostic Action Due to Improper Input Neutralization |
| CVE-2025-41678 | 6.5 MEDIUM | SQL Injection via POST Requests Allowing Configuration Database Manipulation |
| CVE-2025-41679 | 5.3 MEDIUM | Unauthenticated Buffer Overflow in Conftool Service Leading to Denial of Service |
| CVE-2025-41676 | 4.9 MEDIUM | Resource Exhaustion via POST Requests to send-sms Action |
| CVE-2025-41677 | 4.9 MEDIUM | Resource Exhaustion via POST Requests to send-mail Action |
| CVE-2025-41681 | 4.8 MEDIUM | Persistent Cross-Site Scripting via POST Requests Due to Improper Neutralization of Input |
No comments yet