Vulnerabilities in MB connect line
83 resultsVexday analysis
O portfólio de vulnerabilidades da MB connect line acumula 80 CVEs catalogadas, das quais 6 são classificadas como severidade crítica e nenhuma consta atualmente no catálogo KEV da CISA, indicando ausência de exploração ativa confirmada — posição abaixo da média geral do catálogo. Um ponto de atenção significativo é o volume de 48 CVEs surgidas nos últimos 90 dias, sugerindo um ciclo recente de descobertas que merece acompanhamento próximo por equipes de patch management. A falha mais comum é do tipo CWE-89 (injeção de SQL), e a CVE mais perigosa no momento, CVE-2021-33527, apresenta EPSS de 0,0452, sem PoCs públicas conhecidas — o que reduz, mas não elimina, o risco de exploração a curto prazo.
CVE-2026-40838HIGHAuthenticated SQLi in getDeviceScalings functionEPSS 0.3%CVE-2026-40832HIGHAuthenticated SQLi in getDevicegroups functionEPSS 0.3%CVE-2026-40848HIGHAuthenticated SQLi in tag viewEPSS 0.3%CVE-2026-40843HIGHAuthenticated SQLi in alarming viewEPSS 0.3%CVE-2026-40841HIGHAuthenticated SQLi in getProjectTags functionEPSS 0.3%CVE-2026-40837HIGHAuthenticated SQLi in getProjectScalings functionEPSS 0.3%CVE-2026-40844HIGHAuthenticated SQLi in dashboard viewEPSS 0.3%CVE-2026-40846HIGHAuthenticated SQLi in system viewEPSS 0.3%CVE-2026-40842HIGHAuthenticated SQLi in getWidgetTags functionEPSS 0.3%CVE-2026-40839HIGHAuthenticated SQLi in getComponentScalings functionEPSS 0.3%CVE-2026-40847HIGHAuthenticated SQLi in system_tag viewEPSS 0.3%CVE-2026-40835HIGHAuthenticated SQLi in saveObjectFromData functionEPSS 0.3%CVE-2026-40845HIGHAuthenticated SQLi in devices_configuration viewEPSS 0.3%CVE-2021-33526HIGHPrivilege escalation in mbDIALUP <= 3.9R0.0EPSS 0.3%CVE-2026-40824HIGHAuthenticated SQLi in accountstatus viewEPSS 0.2%CVE-2026-40823HIGHAuthenticated SQLi in DevSerialReset functionEPSS 0.2%CVE-2026-40825HIGHAuthenticated SQLi in accountstatus viewEPSS 0.2%CVE-2026-40834HIGHAuthenticated SQLi in saveDashboardLayout functionEPSS 0.2%CVE-2026-40833HIGHAuthenticated SQLi in saveDashboardLayout functionEPSS 0.2%CVE-2026-40836HIGHAuthenticated SQLi in inmessage modelEPSS 0.2%