Mbconnectline develops a focused portfolio of remote-access and connectivity solutions, including its mbconnect24 platform and mbnet embedded networking components, that serve as critical bridges for industrial and enterprise infrastructure management. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around web-application and system-level input handling, with recurring weakness classes including SQL injection, OS command injection, cross-site scripting, and improper privilege management that reflect the authentication and command-execution demands of remote-access gateways. The relatively modest product count belies the vendor's prominence in the industrial connectivity landscape, where a single vulnerability in a widely deployed remote-access appliance can affect many operational environments simultaneously. Defenders should treat this vendor's security advisories as high-priority for any infrastructure relying on mbconnect24 or related appliances, particularly where internet-facing access is involved. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mbconnectline over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33615CRITICAL An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UP | Apr 2, 2026 | 9.1 | 32 | NO | NO |
CVE-2024-45274CRITICAL An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | Oct 15, 2024 | 9.8 | 31 | NO | NO |
CVE-2021-33527CRITICAL In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correct | Aug 2, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-10383CRITICAL An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb | Apr 14, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-33613HIGH Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full | Apr 2, 2026 | 8.8 | 29 | NO | NO |
CVE-2024-45275CRITICAL The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | Oct 15, 2024 | 9.8 | 29 | NO | NO |
CVE-2026-33616HIGH An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a | Apr 2, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-33614HIGH An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SE | Apr 2, 2026 | 7.5 | 27 | NO | NO |
CVE-2023-0985HIGH An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote | Jun 6, 2023 | 8.8 | 26 | NO | NO |
CVE-2020-12528HIGH An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill | Mar 2, 2021 | 7.7 | 25 | NO | NO |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mbconnectline.
Media articles that mention a CVE ID that affects a product developed by Mbconnectline — matched by CVE ID, not by vendor name.