Mbconnectline
Mbconnectline Mbnet.mini Firmware: vulnerabilidades y CVE
Mbconnectline Mbnet.mini Firmware tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-41681 | Media (4.8) | 0.29% | — | 21 jul 2025 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. |
| CVE-2025-41679 | Alta (7.5) | 0.66% | — | 21 jul 2025 | An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. |
| CVE-2025-41678 | Alta (7.2) | 0.61% | — | 21 jul 2025 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. |
| CVE-2025-41677 | Media (4.9) | 0.58% | — | 21 jul 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. |
| CVE-2025-41676 | Media (4.9) | 0.55% | — | 21 jul 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. |
| CVE-2025-41675 | Alta (7.2) | 0.61% | — | 21 jul 2025 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. |
| CVE-2025-41674 | Alta (7.2) | 0.61% | — | 21 jul 2025 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. |
| CVE-2025-41673 | Alta (7.2) | 0.61% | — | 21 jul 2025 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. |
| CVE-2024-45276 | Alta (7.5) | 0.63% | — | 15 oct 2024 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. |
| CVE-2024-45275 | Crítica (9.8) | 0.80% | — | 15 oct 2024 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. |
| CVE-2024-45274 | Crítica (9.8) | 1.5% | — | 15 oct 2024 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. |
| CVE-2024-45273 | Alta (7.8) | 0.09% | — | 15 oct 2024 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. |
| CVE-2024-45271 | Alta (7.8) | 0.31% | — | 15 oct 2024 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.