Vulnerabilidades en MB connect line
83 resultadosAnálisis Vexday
O portfólio de vulnerabilidades da MB connect line acumula 80 CVEs catalogadas, das quais 6 são classificadas como severidade crítica e nenhuma consta atualmente no catálogo KEV da CISA, indicando ausência de exploração ativa confirmada — posição abaixo da média geral do catálogo. Um ponto de atenção significativo é o volume de 48 CVEs surgidas nos últimos 90 dias, sugerindo um ciclo recente de descobertas que merece acompanhamento próximo por equipes de patch management. A falha mais comum é do tipo CWE-89 (injeção de SQL), e a CVE mais perigosa no momento, CVE-2021-33527, apresenta EPSS de 0,0452, sem PoCs públicas conhecidas — o que reduz, mas não elimina, o risco de exploração a curto prazo.
CVE-2024-45272HIGHMB connect line/Helmholz: Generation of weak passwords vulnerabilityEPSS 0.6%CVE-2025-41675HIGHRemote Command Injection via GET in Cloud Server Communication Script Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41673HIGHRemote Command Injection in send_sms Action Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41674HIGHRemote Command Injection in diagnostic Action Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41678MEDIUMSQL Injection via POST Requests Allowing Configuration Database ManipulationEPSS 0.6%CVE-2026-33615CRITICALMB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo EndpointEPSS 0.6%CVE-2025-41677MEDIUMResource Exhaustion via POST Requests to send-mail ActionEPSS 0.6%CVE-2024-23943CRITICALMB connect line: Cloud API access due to a lack of authentication for a critical functionEPSS 0.6%CVE-2026-33616HIGHMB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api EndpointEPSS 0.6%CVE-2026-33614HIGHMB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpointEPSS 0.6%CVE-2026-10521HIGHAuthenticated unintended access to critical program parametersEPSS 0.6%CVE-2025-41676MEDIUMResource Exhaustion via POST Requests to send-sms ActionEPSS 0.6%CVE-2026-40819HIGHUnauthenticated SQLi in sync_data24 taskEPSS 0.5%CVE-2026-40810HIGHUnauthenticated SQLi in userinfo EndpointEPSS 0.5%CVE-2026-40811HIGHUnauthenticated SQLi in ssoabstractserviceEPSS 0.5%CVE-2026-40814HIGHUnauthenticated SQLi in _mb24confi_getTagAlarm functionEPSS 0.5%CVE-2026-40818HIGHUnauthenticated SQLi in _mb24confi_getDevice function functionEPSS 0.5%CVE-2026-40816HIGHUnauthenticated SQLi in _mb24confi_getTagAlarm functionEPSS 0.5%CVE-2026-40812HIGHUnauthenticated SQLi in getLiveValues functionEPSS 0.5%CVE-2026-40817HIGHUnauthenticated SQLi in getAlarmProfiles functionEPSS 0.5%