← Vulnerability feed

Vulnerability record · CVE-2024-45276 · published 15 October 2024

CVE-2024-45276: Mbconnectline mbnet.mini firmware missing authentication for critical function vulnerability

Mbconnectline · Mbnet.Mini Firmware

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

7.5 CVSS 3.1 High EPSS 0.63% · top 52.1% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45274Mbconnectline mbnet.mini firmware missing authentication for critical function vulnerabilityAn unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.EPSS 1.5%9.8CVE-2024-45275Mbconnectline mbnet.mini firmware hard-coded credentials vulnerabilityThe devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affec…EPSS 0.80%7.8CVE-2024-45271Mbconnectline mbnet.mini firmware code injection vulnerabilityAn unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.EPSS 0.31%7.8CVE-2024-45273Mbconnectline mbnet.mini firmware inadequate encryption strength vulnerabilityAn unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encrypt…EPSS 0.09%7.5CVE-2025-41679Mbconnectline mbnet.mini firmware out-of-bounds write vulnerabilityAn unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the netw…EPSS 0.66%7.2CVE-2025-41674Mbconnectline mbnet.mini firmware os command injection vulnerabilityA high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of …EPSS 0.62%7.2CVE-2025-41675Mbconnectline mbnet.mini firmware os command injection vulnerabilityA high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neu…EPSS 0.62%7.2CVE-2025-41678Mbconnectline mbnet.mini firmware sql injection vulnerabilityA high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a…EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2024-45276), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.