MB Connect Line mbCONNECT24和MB Connect Line mymbCONNECT24都是德国MB Connect Line公司的产品。MB Connect Line mbCONNECT24是一套远程服务门户网站。该产品支持远程接入、数据记录和报警等功能。MB Connect Line mymbCONNECT24是一款适用于虚拟环境的内部远程维护解决方案。 MB Connect Line mbCONNECT24和MB Connect Line mymbCONNECT24存在SQ
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Helmholz | myREX24V2 | 0.0.0≤ 2.20.0 |
affected |
2.20.0 |
affected | ||
| Helmholz | myREX24V2.virtual | 0.0.0≤ 2.20.0 |
affected |
2.20.0 |
affected | ||
| MB connect line | mbCONNECT24 | 0.0.0≤ 2.20.0 |
affected |
2.20.0 |
affected | ||
| MB connect line | mymbCONNECT24 | 0.0.0≤ 2.20.0 |
affected |
2.20.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MB connect line | mbCONNECT24 | 0.0.0 ~ 2.20.0 | - |
|
| MB connect line | mymbCONNECT24 | 0.0.0 ~ 2.20.0 | - |
|
| MB connect line | mbCONNECT24 | 2.20.0 | - |
|
| MB connect line | mymbCONNECT24 | 2.20.0 | - |
|
| Helmholz | myREX24V2 | 0.0.0 ~ 2.20.0 | - |
|
| Helmholz | myREX24V2.virtual | 0.0.0 ~ 2.20.0 | - |
|
| Helmholz | myREX24V2 | 2.20.0 | - |
|
| Helmholz | myREX24V2.virtual | 2.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40851 | 8.4 HIGH | Command injection via USB |
| CVE-2026-40810 | 7.5 HIGH | Unauthenticated SQLi in userinfo Endpoint |
| CVE-2026-40817 | 7.5 HIGH | Unauthenticated SQLi in getAlarmProfiles function |
| CVE-2026-40815 | 7.5 HIGH | Unauthenticated SQLi in _mb24api_getUserAccount function |
| CVE-2026-40819 | 7.5 HIGH | Unauthenticated SQLi in sync_data24 task |
| CVE-2026-40850 | 7.5 HIGH | Unauthenticated SQLi in getAccountData function |
| CVE-2026-40814 | 7.5 HIGH | Unauthenticated SQLi in _mb24confi_getTagAlarm function |
| CVE-2026-40818 | 7.5 HIGH | Unauthenticated SQLi in _mb24confi_getDevice function function |
| CVE-2026-40813 | 7.5 HIGH | Unauthenticated SQLi in getLiveValues |
| CVE-2026-40811 | 7.5 HIGH | Unauthenticated SQLi in ssoabstractservice |
| CVE-2026-40812 | 7.5 HIGH | Unauthenticated SQLi in getLiveValues function |
| CVE-2026-40816 | 7.5 HIGH | Unauthenticated SQLi in _mb24confi_getTagAlarm function |
| CVE-2026-40852 | 7.2 HIGH | Command injection via malicious configuration |
| CVE-2026-40833 | 7.1 HIGH | Authenticated SQLi in saveDashboardLayout function |
| CVE-2026-40836 | 7.1 HIGH | Authenticated SQLi in inmessage model |
| CVE-2026-40834 | 7.1 HIGH | Authenticated SQLi in saveDashboardLayout function |
| CVE-2026-40840 | 6.5 MEDIUM | Authenticated SQLi in VerifyCreateLicences function |
| CVE-2026-40842 | 6.5 MEDIUM | Authenticated SQLi in getWidgetTags function |
| CVE-2026-40845 | 6.5 MEDIUM | Authenticated SQLi in devices_configuration view |
| CVE-2026-40844 | 6.5 MEDIUM | Authenticated SQLi in dashboard view |
Showing top 20 of 42 CVEs. View all on vendor page → →
No comments yet