← Vulnerability feed

Vulnerability record · CVE-2025-41678 · published 21 July 2025

CVE-2025-41678: Mbconnectline mbnet.mini firmware sql injection vulnerability

Mbconnectline · Mbnet.Mini Firmware

A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.

7.2 CVSS 3.1 High EPSS 0.61% · top 52.9% CWE-89 · SQL injection
7.2CVSS 3.1 base score
0.61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-41678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45274Mbconnectline mbnet.mini firmware missing authentication for critical function vulnerabilityAn unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.EPSS 1.5%9.8CVE-2024-45275Mbconnectline mbnet.mini firmware hard-coded credentials vulnerabilityThe devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affec…EPSS 0.80%7.8CVE-2024-45271Mbconnectline mbnet.mini firmware code injection vulnerabilityAn unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.EPSS 0.31%7.8CVE-2024-45273Mbconnectline mbnet.mini firmware inadequate encryption strength vulnerabilityAn unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encrypt…EPSS 0.09%7.5CVE-2025-41679Mbconnectline mbnet.mini firmware out-of-bounds write vulnerabilityAn unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the netw…EPSS 0.66%7.5CVE-2024-45276Mbconnectline mbnet.mini firmware missing authentication for critical function vulnerabilityAn unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.EPSS 0.63%7.2CVE-2025-41674Mbconnectline mbnet.mini firmware os command injection vulnerabilityA high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of …EPSS 0.62%7.2CVE-2025-41675Mbconnectline mbnet.mini firmware os command injection vulnerabilityA high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neu…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2025-41678), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.