This page lists publicly disclosed CVE vulnerabilities affecting mbconnectline mbnet.mini_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-41681 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. | [email protected] | 4.8 | 0.27% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41679 | An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. | [email protected] | 5.3 | 0.61% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41678 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. | [email protected] | 6.5 | 0.56% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41677 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. | [email protected] | 4.9 | 0.56% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41676 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. | [email protected] | 4.9 | 0.50% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41675 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. | [email protected] | 7.2 | 0.57% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41674 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. | [email protected] | 7.2 | 0.57% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41673 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. | [email protected] | 7.2 | 0.57% | 2025-07-21 | 2026-06-17 |
| CVE-2024-45276 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | [email protected] | 7.5 | 0.62% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45275 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | [email protected] | 9.8 | 0.80% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45274 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | [email protected] | 9.8 | 1.54% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45273 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | [email protected] | 8.4 | 0.07% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45271 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | [email protected] | 8.4 | 0.31% | 2024-10-15 | 2026-06-17 |