MB Connect Line mbNET Command Injection Vulnerability Allowing Code Execution

Vulnerability

A command injection vulnerability has been identified in MB connect line products mbNET, mbNET.rokey, and mbNET.mini. This vulnerability allows a highly authenticated attacker to inject a payload into the configuration generator, which is then executed by the system. The flaw arises because the device fails to properly validate the configuration value before executing it, leading to unauthorized code execution. As a result, this vulnerability could cause a complete compromise of the affected system.

Impact

Exploitation of this vulnerability allows for command injection, with the potential for full system compromise.

Remediation

Users of mbNET/mbNET.rokey should update to version 8.4.5, and users of mbNET.mini should update to version 3.0.3.

Added: May 27, 2026, 9:20 AM
Updated: May 27, 2026, 9:20 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
3.2
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.