Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MB connect line — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting MB connect line. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MB connect line is a software platform primarily utilized for managing and exchanging electronic documents, including invoices and orders, within business-to-business environments. Security audits have identified thirty-eight Common Vulnerabilities and Exposures (CVEs) associated with the system, indicating a significant historical attack surface. The most prevalent vulnerability classes include remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from inadequate input validation and improper access controls in earlier versions. These defects have allowed attackers to potentially compromise system integrity or access sensitive financial data. While recent updates have addressed many of these issues, the high volume of recorded CVEs suggests a need for rigorous patch management. Organizations deploying this solution must prioritize regular security assessments and ensure all components are updated to mitigate known risks effectively.

CVE ID Title CVSS Severity Published
CVE-2025-3091 MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24 — mbCONNECT24 CWE-639 7.5 High 2025-06-24
CVE-2025-3090 MB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24 — mbCONNECT24 CWE-306 8.2 High 2025-06-24
CVE-2024-23943 MB connect line: Cloud API access due to a lack of authentication for a critical function — mbCONNECT24 CWE-306 9.1 Critical 2025-03-18
CVE-2024-23942 MB connect line: Configuration File on the client workstation is not encrypted — mbCONNECT24 CWE-312 7.1 High 2025-03-18
CVE-2024-45276 MB connect line/Helmholz: tmp directory exposed via webservice — mbNET.mini CWE-306 7.5 High 2024-10-15
CVE-2024-45275 MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwords — mbNET.mini CWE-798 9.8 Critical 2024-10-15
CVE-2024-45274 MB connect line/Helmholz: Remote code execution via confnet service — mbNET.mini CWE-306 9.8 Critical 2024-10-15
CVE-2024-45273 MB connect line/Helmholz: Weak encryption of configuration file — mbNET.mini CWE-261 8.4 High 2024-10-15
CVE-2024-45272 MB connect line/Helmholz: Generation of weak passwords vulnerability — mbCONNECT24 CWE-1391 7.5 High 2024-10-15
CVE-2024-45271 MB connect line/Helmholz: Remote code execution due to improper input validation — mbNET.mini CWE-94 8.4 High 2024-10-15
CVE-2023-1779 Helmholz and MB Connect Line: Account takeover via password reset in multiple products — mbCONNECT24 CWE-863 4.3 Medium 2023-06-06
CVE-2023-0985 Helmholz and MB Connect Line: Account takeover via password reset in multiple products — mbCONNECT24 CWE-639 8.8 High 2023-06-06
CVE-2022-22520 User enumeration vulnerability in MB connect line and Helmholz products — mymbCONNECT24 CWE-204 5.3 Medium 2022-09-14
CVE-2021-34580 Remote user enumeration in mymbCONNECT24, mbCONNECT24 <= 2.9.0 — mymbCONNECT24 CWE-204 7.5 High 2021-10-27
CVE-2021-34575 Information Exposure in mymbCONNECT24, mbCONNECT24 <= 2.8.0 — mymbCONNECT24 CWE-203 7.5 High 2021-08-02
CVE-2021-34574 Password policy evasion in products of MB connect line and Helmholz — mymbCONNECT24 CWE-669 4.3 Medium 2021-08-02
CVE-2021-33527 OS Command Injection in mbDIALUP <= 3.9R0.0 — mbDIALUP CWE-20 9.8 Critical 2021-08-02
CVE-2021-33526 Privilege escalation in mbDIALUP <= 3.9R0.0 — mbDIALUP CWE-269 7.8 High 2021-08-02
CVE-2020-12527 Improper Access Validation in products of MB connect line and Helmholz — mymbCONNECT24 CWE-269 6.5 Medium 2021-03-02
CVE-2020-12530 MB CONNECT LINE mymbCONNECT24 跨站脚本漏洞 — mymbCONNECT24 CWE-79 4.3 Medium 2021-03-02
CVE-2020-12529 MB CONNECT LINE mymbCONNECT24e 代码问题漏洞 — mymbCONNECT24 CWE-918 5.8 Medium 2021-03-02
CVE-2020-12528 mymbCONNECT24 安全漏洞 — mymbCONNECT24 CWE-269 6.5 Medium 2021-03-02

This page lists every published CVE security advisory associated with MB connect line. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.