Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MB connect line — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting MB connect line. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MB connect line is a software platform primarily utilized for managing and exchanging electronic documents, including invoices and orders, within business-to-business environments. Security audits have identified thirty-eight Common Vulnerabilities and Exposures (CVEs) associated with the system, indicating a significant historical attack surface. The most prevalent vulnerability classes include remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from inadequate input validation and improper access controls in earlier versions. These defects have allowed attackers to potentially compromise system integrity or access sensitive financial data. While recent updates have addressed many of these issues, the high volume of recorded CVEs suggests a need for rigorous patch management. Organizations deploying this solution must prioritize regular security assessments and ensure all components are updated to mitigate known risks effectively.

Found 54 results / 82Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-40822 Authenticated SQLi in DevSerialReset function — mbCONNECT24CWE-89 4.9 Medium2026-05-27
CVE-2026-40821 Authenticated SQLi in getAccountByID function — mbCONNECT24CWE-89 4.9 Medium2026-05-27
CVE-2026-40819 Unauthenticated SQLi in sync_data24 task — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40818 Unauthenticated SQLi in _mb24confi_getDevice function function — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40817 Unauthenticated SQLi in getAlarmProfiles function — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40816 Unauthenticated SQLi in _mb24confi_getTagAlarm function — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40815 Unauthenticated SQLi in _mb24api_getUserAccount function — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40814 Unauthenticated SQLi in _mb24confi_getTagAlarm function — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40813 Unauthenticated SQLi in getLiveValues — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40812 Unauthenticated SQLi in getLiveValues function — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40811 Unauthenticated SQLi in ssoabstractservice — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-40810 Unauthenticated SQLi in userinfo Endpoint — mbCONNECT24CWE-89 7.5 High2026-05-27
CVE-2026-33617 MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 Endpoint — mbCONNECT24CWE-497 5.3 Medium2026-04-02
CVE-2026-33616 MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api Endpoint — mbCONNECT24CWE-89 7.5 High2026-04-02
CVE-2026-33615 MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo Endpoint — mbCONNECT24CWE-89 9.1 Critical2026-04-02
CVE-2026-33614 MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpoint — mbCONNECT24CWE-89 7.5 High2026-04-02
CVE-2026-33613 MB connect line mbCONNECT24 vulnerable to RCE in generateSrpArray — mbCONNECT24CWE-78 7.2 High2026-04-02
CVE-2025-3091 MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24 — mbCONNECT24CWE-639 7.5 High2025-06-24
CVE-2025-3090 MB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24 — mbCONNECT24CWE-306 8.2 High2025-06-24
CVE-2024-23943 MB connect line: Cloud API access due to a lack of authentication for a critical function — mbCONNECT24CWE-306 9.1 Critical2025-03-18
CVE-2024-23942 MB connect line: Configuration File on the client workstation is not encrypted — mbCONNECT24CWE-312 7.1 High2025-03-18
CVE-2024-45272 MB connect line/Helmholz: Generation of weak passwords vulnerability — mbCONNECT24CWE-1391 7.5 High2024-10-15
CVE-2023-1779 Helmholz and MB Connect Line: Account takeover via password reset in multiple products — mbCONNECT24CWE-863 4.3 Medium2023-06-06
CVE-2023-0985 Helmholz and MB Connect Line: Account takeover via password reset in multiple products — mbCONNECT24CWE-639 8.8 High2023-06-06

This page lists every published CVE security advisory associated with MB connect line. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.