← Vulnerability feed

Vulnerability record · CVE-2026-33614 · published 2 April 2026

CVE-2026-33614: Mbconnectline mbconnect24 sql injection vulnerability

Mbconnectline · Mbconnect24

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

7.5 CVSS 3.1 High EPSS 0.57% · top 55.1% CWE-89 · SQL injection
7.5CVSS 3.1 base score
0.57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33614 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-35565Mbconnectline mbconnect24 improper restriction of authentication attempts vulnerabilityAn issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.EPSS 1.1%9.8CVE-2020-10383Mbconnectline mbconnect24 vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remo…EPSS 1.8%9.1CVE-2026-33615Mbconnectline mbconnect24 sql injection vulnerabilityAn unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization …EPSS 0.59%8.8CVE-2026-33613Mbconnectline mbconnect24 os command injection vulnerabilityDue to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpAr…EPSS 0.69%8.8CVE-2023-0985Mbconnectline mbconnect24 insecure direct object reference vulnerabilityAn Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2…EPSS 0.79%8.8CVE-2020-10382Mbconnectline mbconnect24 vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote…EPSS 1.9%7.8CVE-2024-45273Mbconnectline mbnet.mini firmware inadequate encryption strength vulnerabilityAn unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encrypt…EPSS 0.09%7.8CVE-2020-35567Mbconnectline mbconnect24 hard-coded credentials vulnerabilityAn issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but …EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2026-33614), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.