← Vulnerability feed

Vulnerability record · CVE-2026-33613 · published 2 April 2026

CVE-2026-33613: Mbconnectline mbconnect24 os command injection vulnerability

Mbconnectline · Mbconnect24

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data to the user table.

8.8 CVSS 3.1 High EPSS 0.69% · top 49.2% CWE-78 · OS command injection
8.8CVSS 3.1 base score
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data to the user table.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33613 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-35565Mbconnectline mbconnect24 improper restriction of authentication attempts vulnerabilityAn issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.EPSS 1.1%9.8CVE-2020-10383Mbconnectline mbconnect24 vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remo…EPSS 1.8%9.1CVE-2026-33615Mbconnectline mbconnect24 sql injection vulnerabilityAn unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization …EPSS 0.59%8.8CVE-2023-0985Mbconnectline mbconnect24 insecure direct object reference vulnerabilityAn Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2…EPSS 0.79%8.8CVE-2020-10382Mbconnectline mbconnect24 vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote…EPSS 1.9%7.8CVE-2024-45273Mbconnectline mbnet.mini firmware inadequate encryption strength vulnerabilityAn unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encrypt…EPSS 0.09%7.8CVE-2020-35567Mbconnectline mbconnect24 hard-coded credentials vulnerabilityAn issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but …EPSS 0.25%7.8CVE-2020-10384Mbconnectline mbconnect24 improper privilege management vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escal…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-33613), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.