MB connect line mbNET.mini
cpe:2.3:h:mbconnectline:mbnet.mini:*:*:*:*:*:*:*, +1 more
- <= 2.3.2
A command injection vulnerability has been identified in MB connect line mbNET.mini devices running firmware prior to 2.3.3. This vulnerability allows high-privileged remote attackers to execute arbitrary system commands by sending POST requests to the send_sms action. The issue arises from improper handling of special elements used in operating system commands, which could be exploited to gain unauthorized command execution on the affected devices.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device, potentially leading to full control over the device.
Users are advised to update to the latest version, 2.3.3.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.