CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. |
2Helmholz Mbconnectline15Mbconnect24 Mbnet.mini FirmwareMbnet.rokey Firmware+12 moreJun 17, 2026 Oct 15, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. |