Product
mbconnectline mbnet.mini firmware
13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-41681
CVE-2025-41679
CVE-2025-41678
CVE-2025-41677
CVE-2025-41676
CVE-2025-41675
CVE-2025-41674
CVE-2025-41673
CVE-2024-45276
CVE-2024-45275
CVE-2024-45274
CVE-2024-45273
CVE-2024-45271
< 2.3.3
A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements use
< 2.3.3
An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that af
< 2.3.3
A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special
< 2.3.3
A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-
< 2.3.3
A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-
< 2.3.3
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script
< 2.3.3
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper
< 2.3.3
A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper n
< 2.3.1
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
< 2.3.1
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full c
< 2.3.1
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
< 2.3.1
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementa
< 2.3.1
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.