mbconnectline CVE Vulnerabilities & Metrics

Focus on mbconnectline vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About mbconnectline Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with mbconnectline. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total mbconnectline CVEs: 35
Earliest CVE date: 14 Apr 2020, 17:15 UTC
Latest CVE date: 15 Oct 2024, 11:15 UTC

Latest CVE reference: CVE-2024-45273

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -33.33%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -33.33%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical mbconnectline CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.29

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 24
7.0-8.9 3
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS mbconnectline CVEs

These are the five CVEs with the highest CVSS scores for mbconnectline, sorted by severity first and recency.

All CVEs for mbconnectline

CVE-2024-45273 mbconnectline vulnerability CVSS: 0 15 Oct 2024, 11:15 UTC

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

CVE-2024-45272 mbconnectline vulnerability CVSS: 0 15 Oct 2024, 11:15 UTC

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.

CVE-2023-4834 mbconnectline vulnerability CVSS: 0 16 Oct 2023, 09:15 UTC

In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.

CVE-2023-1779 mbconnectline vulnerability CVSS: 0 06 Jun 2023, 11:15 UTC

Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another accounts contact information.

CVE-2023-0985 mbconnectline vulnerability CVSS: 0 06 Jun 2023, 11:15 UTC

An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore fully compromise the account.

CVE-2022-22520 mbconnectline vulnerability CVSS: 0 14 Sep 2022, 14:15 UTC

A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.

CVE-2021-34580 mbconnectline vulnerability CVSS: 5.0 27 Oct 2021, 11:15 UTC

In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.

CVE-2021-34575 mbconnectline vulnerability CVSS: 5.0 02 Aug 2021, 11:15 UTC

In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of response the server sends.

CVE-2021-34574 mbconnectline vulnerability CVSS: 4.0 02 Aug 2021, 11:15 UTC

In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

CVE-2021-33527 mbconnectline vulnerability CVSS: 10.0 02 Aug 2021, 11:15 UTC

In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service.

CVE-2021-33526 mbconnectline vulnerability CVSS: 7.2 02 Aug 2021, 11:15 UTC

In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.

CVE-2020-12530 mbconnectline vulnerability CVSS: 4.3 02 Mar 2021, 22:15 UTC

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a get parameter.

CVE-2020-12529 mbconnectline vulnerability CVSS: 5.0 02 Mar 2021, 22:15 UTC

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.

CVE-2020-12528 mbconnectline vulnerability CVSS: 4.0 02 Mar 2021, 22:15 UTC

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.

CVE-2020-12527 mbconnectline vulnerability CVSS: 6.8 02 Mar 2021, 22:15 UTC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.

CVE-2020-35570 mbconnectline vulnerability CVSS: 5.0 16 Feb 2021, 16:15 UTC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

CVE-2020-35569 mbconnectline vulnerability CVSS: 4.3 16 Feb 2021, 16:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.

CVE-2020-35568 mbconnectline vulnerability CVSS: 4.0 16 Feb 2021, 16:15 UTC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users and devices in the account.

CVE-2020-35567 mbconnectline vulnerability CVSS: 4.6 16 Feb 2021, 16:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.

CVE-2020-35566 mbconnectline vulnerability CVSS: 5.0 16 Feb 2021, 16:15 UTC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.

CVE-2020-35565 mbconnectline vulnerability CVSS: 5.0 16 Feb 2021, 16:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.

CVE-2020-35564 mbconnectline vulnerability CVSS: 5.0 16 Feb 2021, 16:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.

CVE-2020-35563 mbconnectline vulnerability CVSS: 3.5 16 Feb 2021, 16:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.

CVE-2020-35561 mbconnectline vulnerability CVSS: 5.0 16 Feb 2021, 16:15 UTC

An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.

CVE-2020-35560 mbconnectline vulnerability CVSS: 5.8 16 Feb 2021, 16:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.

CVE-2020-35559 mbconnectline vulnerability CVSS: 4.0 16 Feb 2021, 16:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.

CVE-2020-35558 mbconnectline vulnerability CVSS: 5.0 16 Feb 2021, 16:15 UTC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.

CVE-2020-35557 mbconnectline vulnerability CVSS: 4.0 16 Feb 2021, 16:15 UTC

An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.

CVE-2020-24568 mbconnectline vulnerability CVSS: 4.0 02 Oct 2020, 19:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.

CVE-2020-24570 mbconnectline vulnerability CVSS: 4.3 30 Sep 2020, 18:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.

CVE-2020-24569 mbconnectline vulnerability CVSS: 4.0 30 Sep 2020, 18:15 UTC

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.

CVE-2020-10384 mbconnectline vulnerability CVSS: 7.2 14 Apr 2020, 18:15 UTC

An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escalation from the www-data account to the root account.

CVE-2020-10383 mbconnectline vulnerability CVSS: 7.5 14 Apr 2020, 17:15 UTC

An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb24sysapi module.

CVE-2020-10382 mbconnectline vulnerability CVSS: 6.5 14 Apr 2020, 17:15 UTC

An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote code execution in the backup-scheduler.

CVE-2020-10381 mbconnectline vulnerability CVSS: 5.0 14 Apr 2020, 17:15 UTC

An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing attackers to discover database and table names.