CVE-2025-41674
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.
Affected (1)
Products: Mbconnectline: Mbnet.mini Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.3 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbnet.mini | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Timeline
No history available yet.