VendorsMB Connect Linembconnect24any version
Vulnerabilities

MB Connect Line mbCONNECT24 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2020-10383
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb24sysapi module.
Published 2020-04-14 · Modified
9.8EPSS 0.018
CVE-2020-35565
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
Published 2021-02-16 · Modified
9.8EPSS 0.011
CVE-2026-33615
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo Endpoint
Published 2026-04-02 · Analyzed
9.1EPSS 0.006
CVE-2020-10382
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote code execution in the backup-scheduler.
Published 2020-04-14 · Modified
8.8EPSS 0.019
CVE-2023-0985
Helmholz and MB Connect Line: Account takeover via password reset in multiple products
Published 2023-06-06 · Modified
8.8EPSS 0.008
CVE-2026-33613
MB connect line mbCONNECT24 vulnerable to RCE in generateSrpArray
Published 2026-04-02 · Analyzed
8.8EPSS 0.007
CVE-2024-45273
MB connect line/Helmholz: Weak encryption of configuration file
Published 2024-10-15 · Modified
8.4EPSS 0.001
CVE-2020-10384
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escalation from the www-data account to the root account.
Published 2020-04-14 · Modified
7.8EPSS 0.003
CVE-2020-35567
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.
Published 2021-02-16 · Modified
7.8EPSS 0.002
CVE-2020-12528
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.
Published 2021-03-02 · Modified
7.7EPSS 0.009
CVE-2020-35558
SSRF in products of MB connect line and Helmholz
Published 2021-02-16 · Modified
7.5EPSS 0.015
CVE-2021-34580
Remote user enumeration in mymbCONNECT24, mbCONNECT24 <= 2.9.0
Published 2021-10-27 · Modified
7.5EPSS 0.010
CVE-2021-34575
Information Exposure in mymbCONNECT24, mbCONNECT24 <= 2.8.0
Published 2021-08-02 · Modified
7.5EPSS 0.010
CVE-2020-35564
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.
Published 2021-02-16 · Modified
7.5EPSS 0.009
CVE-2024-45272
MB connect line/Helmholz: Generation of weak passwords vulnerability
Published 2024-10-15 · Modified
7.5EPSS 0.006
CVE-2026-33614
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpoint
Published 2026-04-02 · Analyzed
7.5EPSS 0.006
CVE-2026-33616
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api Endpoint
Published 2026-04-02 · Analyzed
7.5EPSS 0.006
CVE-2020-12527
Improper Access Validation in products of MB connect line and Helmholz
Published 2021-03-02 · Modified
6.8EPSS 0.010
CVE-2020-35557
Improper Access Validation in products of MB connect line and Helmholz
Published 2021-02-16 · Modified
6.5EPSS 0.010
CVE-2020-24568
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.
Published 2020-10-02 · Modified
6.5EPSS 0.008
CVE-2020-24570
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.
Published 2020-09-29 · Modified
6.5EPSS 0.005
CVE-2020-35560
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.
Published 2021-02-16 · Modified
6.1EPSS 0.007
CVE-2020-35569
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.
Published 2021-02-16 · Modified
6.1EPSS 0.007
CVE-2020-12530
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a get parameter.
Published 2021-03-02 · Modified
6.1EPSS 0.006
CVE-2020-12529
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.
Published 2021-03-02 · Modified
5.8EPSS 0.008
CVE-2020-35563
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.
Published 2021-02-16 · Modified
5.4EPSS 0.005
CVE-2020-35570
Foreced Browsing vulnerability in products of MB connect line and Helmholz
Published 2021-02-16 · Modified
5.3EPSS 0.012
CVE-2020-35566
Local file inclusion vulnerability in products of MB connect line and Helmholz
Published 2021-02-16 · Modified
5.3EPSS 0.012
CVE-2020-35561
SSRF in variuos products of MB connect line and Helmholz
Published 2021-02-16 · Modified
5.3EPSS 0.012
CVE-2020-10381
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing attackers to discover database and table names.
Published 2020-04-14 · Modified
5.3EPSS 0.011
CVE-2022-22520
User enumeration vulnerability in MB connect line and Helmholz products
Published 2022-09-14 · Modified
5.3EPSS 0.010
CVE-2026-33617
MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 Endpoint
Published 2026-04-02 · Analyzed
5.3EPSS 0.004
CVE-2020-35568
Sensitive Information Exposure in products of MB connect line and Helmholz
Published 2021-02-16 · Modified
4.3EPSS 0.010
CVE-2020-35559
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.
Published 2021-02-16 · Modified
4.3EPSS 0.008
CVE-2020-24569
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.
Published 2020-09-29 · Modified
4.3EPSS 0.007
CVE-2021-34574
Password policy evasion in products of MB connect line and Helmholz
Published 2021-08-02 · Modified
4.3EPSS 0.007
CVE-2023-1779
Helmholz and MB Connect Line: Account takeover via password reset in multiple products
Published 2023-06-06 · Modified
4.3EPSS 0.005
CVE-2023-4834
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.
Published 2023-10-16 · Modified
4.3EPSS 0.003