MB Connect Line mbNET.mini是德国MB Connect Line公司的一款远程接入路由器。 MB Connect Line mbNET.mini 2.3.3之前版本存在SQL注入漏洞,该漏洞源于对SQL语句中特殊元素中和不当,可能导致修改配置数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MB connect line | mbNET.mini | 0.0.0 ~ 2.3.3 | - |
|
| Helmholz | REX 100 | 0.0.0 ~ 2.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-41675 | 7.2 HIGH | Remote Command Injection via GET in Cloud Server Communication Script Due to Improper Inpu |
| CVE-2025-41673 | 7.2 HIGH | Remote Command Injection in send_sms Action Due to Improper Input Neutralization |
| CVE-2025-41674 | 7.2 HIGH | Remote Command Injection in diagnostic Action Due to Improper Input Neutralization |
| CVE-2025-41679 | 5.3 MEDIUM | Unauthenticated Buffer Overflow in Conftool Service Leading to Denial of Service |
| CVE-2025-41676 | 4.9 MEDIUM | Resource Exhaustion via POST Requests to send-sms Action |
| CVE-2025-41677 | 4.9 MEDIUM | Resource Exhaustion via POST Requests to send-mail Action |
| CVE-2025-41681 | 4.8 MEDIUM | Persistent Cross-Site Scripting via POST Requests Due to Improper Neutralization of Input |
No comments yet