VendorsMB Connect Linembnet.mini_firmwareall versions
Vulnerabilities

MB Connect Line mbNET.mini Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2024-45274
MB connect line/Helmholz: Remote code execution via confnet service
Published 2024-10-15 · Modified
9.8EPSS 0.015
CVE-2024-45275
MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwords
Published 2024-10-15 · Modified
9.8EPSS 0.008
CVE-2024-45271
MB connect line/Helmholz: Remote code execution due to improper input validation
Published 2024-10-15 · Modified
8.4EPSS 0.003
CVE-2024-45273
MB connect line/Helmholz: Weak encryption of configuration file
Published 2024-10-15 · Modified
8.4EPSS 0.001
CVE-2025-41679
Unauthenticated Buffer Overflow in Conftool Service Leading to Denial of Service
Published 2025-07-21 · Analyzed
7.5EPSS 0.007
CVE-2024-45276
MB connect line/Helmholz: tmp directory exposed via webservice
Published 2024-10-15 · Modified
7.5EPSS 0.006
CVE-2025-41673
Remote Command Injection in send_sms Action Due to Improper Input Neutralization
Published 2025-07-21 · Analyzed
7.2EPSS 0.006
CVE-2025-41674
Remote Command Injection in diagnostic Action Due to Improper Input Neutralization
Published 2025-07-21 · Analyzed
7.2EPSS 0.006
CVE-2025-41675
Remote Command Injection via GET in Cloud Server Communication Script Due to Improper Input Neutralization
Published 2025-07-21 · Analyzed
7.2EPSS 0.006
CVE-2025-41678
SQL Injection via POST Requests Allowing Configuration Database Manipulation
Published 2025-07-21 · Analyzed
7.2EPSS 0.006
CVE-2025-41677
Resource Exhaustion via POST Requests to send-mail Action
Published 2025-07-21 · Analyzed
4.9EPSS 0.006
CVE-2025-41676
Resource Exhaustion via POST Requests to send-sms Action
Published 2025-07-21 · Analyzed
4.9EPSS 0.006
CVE-2025-41681
Persistent Cross-Site Scripting via POST Requests Due to Improper Neutralization of Input
Published 2025-07-21 · Analyzed
4.8EPSS 0.003