MB Connect Line mbNET.mini Command Injection Vulnerability in send_sms Action

Vulnerability

A command injection vulnerability has been identified in MB connect line mbNET.mini devices running firmware prior to 2.3.3. This vulnerability allows high-privileged remote attackers to execute arbitrary system commands by sending POST requests to the send_sms action. The issue arises from improper handling of special elements used in operating system commands, which could be exploited to gain unauthorized command execution on the affected devices.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device, potentially leading to full control over the device.

Remediation

Users are advised to update to the latest version, 2.3.3.

Added: Jul 21, 2025, 10:25 AM
Updated: Jul 21, 2025, 10:25 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
5.0
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.