MB Connect Line mbNET和MB Connect Line mbNET.mini都是德国MB Connect Line公司的产品。MB Connect Line mbNET是一款工业路由器。MB Connect Line mbNET.mini是一款远程接入路由器。 MB Connect Line mbNET和MB Connect Line mbNET.mini存在安全漏洞,该漏洞源于本地攻击者可通过USB设备上的特制文件对cfgparser执行混淆攻击,可能导致代码执行,造成完全机密性、完
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Helmholz | REX100 | 0.0.0≤ 3.0.2 |
affected |
3.0.2 |
affected | ||
| Helmholz | REX200/250 | 0.0.0≤ 8.4.4 |
affected |
8.4.4 |
affected | ||
| MB connect line | mbNET.mini | 0.0.0≤ 3.0.2 |
affected |
3.0.2 |
affected | ||
| MB connect line | mbNET/mbNET.rokey | 0.0.0≤ 8.4.4 |
affected |
8.4.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MB connect line | mbNET/mbNET.rokey | 0.0.0 ~ 8.4.4 | - |
|
| MB connect line | mbNET.mini | 0.0.0 ~ 3.0.2 | - |
|
| MB connect line | mbNET/mbNET.rokey | 8.4.4 | - |
|
| MB connect line | mbNET.mini | 3.0.2 | - |
|
| Helmholz | REX200/250 | 0.0.0 ~ 8.4.4 | - |
|
| Helmholz | REX100 | 0.0.0 ~ 3.0.2 | - |
|
| Helmholz | REX200/250 | 8.4.4 | - |
|
| Helmholz | REX100 | 3.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40810 | 7.5 HIGH | Unauthenticated SQLi in userinfo Endpoint |
| CVE-2026-40817 | 7.5 HIGH | Unauthenticated SQLi in getAlarmProfiles function |
| CVE-2026-40815 | 7.5 HIGH | Unauthenticated SQLi in _mb24api_getUserAccount function |
| CVE-2026-40819 | 7.5 HIGH | Unauthenticated SQLi in sync_data24 task |
| CVE-2026-40850 | 7.5 HIGH | Unauthenticated SQLi in getAccountData function |
| CVE-2026-40814 | 7.5 HIGH | Unauthenticated SQLi in _mb24confi_getTagAlarm function |
| CVE-2026-40818 | 7.5 HIGH | Unauthenticated SQLi in _mb24confi_getDevice function function |
| CVE-2026-40813 | 7.5 HIGH | Unauthenticated SQLi in getLiveValues |
| CVE-2026-40816 | 7.5 HIGH | Unauthenticated SQLi in _mb24confi_getTagAlarm function |
| CVE-2026-40811 | 7.5 HIGH | Unauthenticated SQLi in ssoabstractservice |
| CVE-2026-40812 | 7.5 HIGH | Unauthenticated SQLi in getLiveValues function |
| CVE-2026-40852 | 7.2 HIGH | Command injection via malicious configuration |
| CVE-2026-40833 | 7.1 HIGH | Authenticated SQLi in saveDashboardLayout function |
| CVE-2026-40836 | 7.1 HIGH | Authenticated SQLi in inmessage model |
| CVE-2026-40834 | 7.1 HIGH | Authenticated SQLi in saveDashboardLayout function |
| CVE-2026-40832 | 6.5 MEDIUM | Authenticated SQLi in getDevicegroups function |
| CVE-2026-40842 | 6.5 MEDIUM | Authenticated SQLi in getWidgetTags function |
| CVE-2026-40845 | 6.5 MEDIUM | Authenticated SQLi in devices_configuration view |
| CVE-2026-40844 | 6.5 MEDIUM | Authenticated SQLi in dashboard view |
| CVE-2026-40838 | 6.5 MEDIUM | Authenticated SQLi in getDeviceScalings function |
Showing top 20 of 42 CVEs. View all on vendor page → →
No comments yet