Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

mbCONNECT24 — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in mbCONNECT24, with AI-generated Chinese analysis, references, and POCs.

This page documents the security landscape for mbCONNECT24, an industrial software platform by Moeller Intelligent Digital Solutions, specifically focusing on common weakness enumeration vulnerabilities. It aggregates a comprehensive collection of disclosed security issues, including remote code execution flaws, improper access control errors, and cross-site scripting defects, covering advisories released from the platform’s inception through recent updates. Users can utilize this resource to systematically track vendor security advisories and monitor the lifecycle of reported flaws within the mbCONNECT24 ecosystem. The collection enables detailed analysis of specific weakness classes, allowing security professionals to understand the nature of the risks associated with this software. Additionally, it provides a historical view of vulnerability disclosures, helping administrators assess the evolution of security posture and prioritize remediation efforts based on past incidents. By centralizing this data, the page serves as a reference for identifying patterns in how the vendor responds to different types of security threats. This information is critical for IT administrators and security auditors who need to evaluate the integrity of their industrial control systems. The aggregated data reflects known exploitable conditions and configuration weaknesses that have been publicly documented. Reviewing these entries allows stakeholders to better understand the attack surface of mbCONNECT24 and implement appropriate mitigations. The content is strictly factual, derived from official vendor communications and recognized vulnerability databases, ensuring accuracy for technical decision-making.

Vendor: MB Connect Line

CVE IDTitleCVSSSeverityPublished
CVE-2026-40822 Authenticated SQLi in DevSerialReset function CWE-89 4.9 Medium2026-05-27
CVE-2026-40821 Authenticated SQLi in getAccountByID function CWE-89 4.9 Medium2026-05-27
CVE-2026-40819 Unauthenticated SQLi in sync_data24 task CWE-89 7.5 High2026-05-27
CVE-2026-40818 Unauthenticated SQLi in _mb24confi_getDevice function function CWE-89 7.5 High2026-05-27
CVE-2026-40817 Unauthenticated SQLi in getAlarmProfiles function CWE-89 7.5 High2026-05-27
CVE-2026-40816 Unauthenticated SQLi in _mb24confi_getTagAlarm function CWE-89 7.5 High2026-05-27
CVE-2026-40815 Unauthenticated SQLi in _mb24api_getUserAccount function CWE-89 7.5 High2026-05-27
CVE-2026-40814 Unauthenticated SQLi in _mb24confi_getTagAlarm function CWE-89 7.5 High2026-05-27
CVE-2026-40813 Unauthenticated SQLi in getLiveValues CWE-89 7.5 High2026-05-27
CVE-2026-40812 Unauthenticated SQLi in getLiveValues function CWE-89 7.5 High2026-05-27
CVE-2026-40811 Unauthenticated SQLi in ssoabstractservice CWE-89 7.5 High2026-05-27
CVE-2026-40810 Unauthenticated SQLi in userinfo Endpoint CWE-89 7.5 High2026-05-27
CVE-2026-33617 MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 Endpoint CWE-497 5.3 Medium2026-04-02
CVE-2026-33616 MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api Endpoint CWE-89 7.5 High2026-04-02
CVE-2026-33615 MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo Endpoint CWE-89 9.1 Critical2026-04-02
CVE-2026-33614 MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpoint CWE-89 7.5 High2026-04-02
CVE-2026-33613 MB connect line mbCONNECT24 vulnerable to RCE in generateSrpArray CWE-78 7.2 High2026-04-02
CVE-2025-3091 MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24 CWE-639 7.5 High2025-06-24
CVE-2025-3090 MB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24 CWE-306 8.2 High2025-06-24
CVE-2024-23943 MB connect line: Cloud API access due to a lack of authentication for a critical function CWE-306 9.1 Critical2025-03-18
CVE-2024-23942 MB connect line: Configuration File on the client workstation is not encrypted CWE-312 7.1 High2025-03-18
CVE-2024-45272 MB connect line/Helmholz: Generation of weak passwords vulnerability CWE-1391 7.5 High2024-10-15
CVE-2023-4834 MB connect line mbCONNECT24和mymbCONNECT24 安全漏洞 CWE-269 4.3 Medium2023-10-16
CVE-2023-1779 Helmholz and MB Connect Line: Account takeover via password reset in multiple products CWE-863 4.3 Medium2023-06-06
CVE-2023-0985 Helmholz and MB Connect Line: Account takeover via password reset in multiple products CWE-639 8.8 High2023-06-06

All 55 known CVE vulnerabilities affecting mbCONNECT24 with full Chinese analysis, references, and POCs where available.