MB connect line mbNET
cpe:2.3:o:mbconnectline:mbnet_firmware:*:*:*:*:*:*:*
- <= 8.4.4
- 8.4.4
A command injection vulnerability has been identified in MB connect line products mbNET, mbNET.rokey, and mbNET.mini. This vulnerability allows a highly authenticated attacker to inject a payload into the configuration generator, which is then executed by the system. The flaw arises because the device fails to properly validate the configuration value before executing it, leading to unauthorized code execution. As a result, this vulnerability could cause a complete compromise of the affected system.
Exploitation of this vulnerability allows for command injection, with the potential for full system compromise.
Users of mbNET/mbNET.rokey should update to version 8.4.5, and users of mbNET.mini should update to version 3.0.3.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.