CVEs (13)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mbconnectline 1Mbnet.mini Firmware Jun 17, 2026 Jul 21, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. |
An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. |
A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. |
1Mbconnectline 1Mbnet.mini Firmware Jun 17, 2026 Jul 21, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. |
1Mbconnectline 1Mbnet.mini Firmware Jun 17, 2026 Jul 21, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. |
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. |
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. |
A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. |
2Helmholz Mbconnectline15Mbconnect24 Mbnet.mini FirmwareMbnet.rokey Firmware+12 moreJun 17, 2026 Oct 15, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. |