Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-3091— MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24

CVSS 7.5 · High EPSS 0.43% · P63
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-3091

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24
Source: NVD (National Vulnerability Database)
Vulnerability Description
An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: NVD (National Vulnerability Database)
Vulnerability Title
Helmholz myREX24、MB Connect Line mymbCONNECT24和MB Connect Line mbCONNECT24 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MB Connect Line mbCONNECT24等都是德国MB Connect Line公司的产品。MB Connect Line mbCONNECT24是一套远程服务门户网站。MB Connect Line mymbCONNECT24是一款适用于虚拟环境的内部远程维护解决方案。Helmholz myREX24等都是Helmholz公司的产品。Helmholz myREX24是一个集成系统,用于访问机器或系统的组件,以进行远程维护和远程诊断。 Helmholz myREX24、MB Connect
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MB connect linembCONNECT24 0 ~ 2.16.5 -
MB connect linemymbCONNECT24 0 ~ 2.18.0 -
MB connect linemymbCONNECT24 0 ~ 2.18.0 -
MB connect linemymbCONNECT24 0 ~ 2.16.5 -
HelmholzmyREX24 0 ~ 2.18.0 -
HelmholzmyREX24 0 ~ 2.16.5 -
HelmholzmyREX24.virtual 0 ~ 2.18.0 -
HelmholzmyREX24.virtual 0 ~ 2.16.5 -

II. Public POCs for CVE-2025-3091

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-3091

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-3091

No comments yet


Leave a comment