Vulnerabilidades en MB connect line
83 resultadosAnálisis Vexday
O portfólio de vulnerabilidades da MB connect line acumula 80 CVEs catalogadas, das quais 6 são classificadas como severidade crítica e nenhuma consta atualmente no catálogo KEV da CISA, indicando ausência de exploração ativa confirmada — posição abaixo da média geral do catálogo. Um ponto de atenção significativo é o volume de 48 CVEs surgidas nos últimos 90 dias, sugerindo um ciclo recente de descobertas que merece acompanhamento próximo por equipes de patch management. A falha mais comum é do tipo CWE-89 (injeção de SQL), e a CVE mais perigosa no momento, CVE-2021-33527, apresenta EPSS de 0,0452, sem PoCs públicas conhecidas — o que reduz, mas não elimina, o risco de exploração a curto prazo.
CVE-2026-40849HIGHAuthenticated SQLi in user_alarmprofile viewEPSS 0.4%CVE-2026-40832HIGHAuthenticated SQLi in getDevicegroups functionEPSS 0.4%CVE-2026-40837HIGHAuthenticated SQLi in getProjectScalings functionEPSS 0.4%CVE-2026-40846HIGHAuthenticated SQLi in system viewEPSS 0.4%CVE-2026-40839HIGHAuthenticated SQLi in getComponentScalings functionEPSS 0.4%CVE-2026-33617MEDIUMMB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 EndpointEPSS 0.4%CVE-2026-40824HIGHAuthenticated SQLi in accountstatus viewEPSS 0.4%CVE-2026-40829HIGHAuthenticated SQLi in UpdateParam functionEPSS 0.4%CVE-2026-40827HIGHAuthenticated SQLi in _RemoveRequest functionEPSS 0.4%CVE-2026-40825HIGHAuthenticated SQLi in accountstatus viewEPSS 0.4%CVE-2026-40830HIGHAuthenticated SQLi in UpdateParam functionEPSS 0.4%CVE-2026-40823HIGHAuthenticated SQLi in DevSerialReset functionEPSS 0.4%CVE-2026-40828HIGHAuthenticated SQLi in DeleteSysLogEntry functionEPSS 0.4%CVE-2026-40836HIGHAuthenticated SQLi in inmessage modelEPSS 0.4%CVE-2026-40834HIGHAuthenticated SQLi in saveDashboardLayout functionEPSS 0.4%CVE-2026-40833HIGHAuthenticated SQLi in saveDashboardLayout functionEPSS 0.4%CVE-2025-3091HIGHMB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24EPSS 0.4%CVE-2024-45271HIGHMB connect line/Helmholz: Remote code execution due to improper input validationEPSS 0.3%CVE-2025-41681MEDIUMPersistent Cross-Site Scripting via POST Requests Due to Improper Neutralization of InputEPSS 0.3%CVE-2021-33526HIGHPrivilege escalation in mbDIALUP <= 3.9R0.0EPSS 0.3%