MB Connect Line mbNET.mini Improper OS Command Neutralization Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A vulnerability exists in MB connect line mbNET.mini devices running firmware prior to 2.3.3. This vulnerability allows high-privileged remote attackers to execute arbitrary system commands. The issue arises from improper handling of special elements used in operating system commands, which can be exploited through GET requests in the cloud server communication script.

Impact

Exploitation of this vulnerability allows for full control over the affected device.

Remediation

Users are advised to update to the latest version, 2.3.3.

Added: Jul 21, 2025, 10:20 AM
Updated: Jul 21, 2025, 10:20 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
5.0
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.