MB Connect Line mbNET.mini OS Command Injection Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A command injection vulnerability has been identified in MB connect line mbNET.mini devices running firmware prior to 2.3.3. This vulnerability allows high-privileged remote attackers to execute arbitrary system commands by sending POST requests through the diagnostic action. The issue arises from improper handling of special elements used in operating system commands.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device, potentially leading to full control over the device.

Remediation

Users are advised to update to the latest version, 2.3.3.

Added: Jul 21, 2025, 10:23 AM
Updated: Jul 21, 2025, 10:23 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
5.0
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.