Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mbconnectline

First CVE: Apr 14, 2020Active for: 6 yearsTotal CVEs: 52
29.3
VTI Score
Low

Mbconnectline develops a focused portfolio of remote-access and connectivity solutions, including its mbconnect24 platform and mbnet embedded networking components, that serve as critical bridges for industrial and enterprise infrastructure management. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around web-application and system-level input handling, with recurring weakness classes including SQL injection, OS command injection, cross-site scripting, and improper privilege management that reflect the authentication and command-execution demands of remote-access gateways. The relatively modest product count belies the vendor's prominence in the industrial connectivity landscape, where a single vulnerability in a widely deployed remote-access appliance can affect many operational environments simultaneously. Defenders should treat this vendor's security advisories as high-priority for any infrastructure relying on mbconnect24 or related appliances, particularly where internet-facing access is involved. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
52
Total CVEs
More Total CVEs than 98% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mbconnectline over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2020
6 years ago
Most Recent CVE
Apr 2, 2026
113 days ago

Products(19 total)

Top CVEs

Signals from CVEs in this vendor scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33615CRITICAL
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UP
Apr 2, 20269.132NONO
CVE-2024-45274CRITICAL
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
Oct 15, 20249.831NONO
CVE-2021-33527CRITICAL
In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correct
Aug 2, 20219.831NONO
CVE-2020-10383CRITICAL
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb
Apr 14, 20209.831NONO
CVE-2026-33613HIGH
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full
Apr 2, 20268.829NONO
CVE-2024-45275CRITICAL
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Oct 15, 20249.829NONO
CVE-2026-33616HIGH
An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a
Apr 2, 20267.527NONO
CVE-2026-33614HIGH
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SE
Apr 2, 20267.527NONO
CVE-2023-0985HIGH
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote
Jun 6, 20238.826NONO
CVE-2020-12528HIGH
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill
Mar 2, 20217.725NONO
View all 52 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products52 CVEs
46%
42%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (9.6%)
Network47 (90.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low52 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None46 (88.5%)
Unknown0 (0.0%)
Required6 (11.5%)
Privileges Required
Low19 (36.5%)
High7 (13.5%)
None26 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mbconnectline.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mbconnectline — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mbconnectline's Products

View all 2 CNAs →

Top CWEs