Vulnerabilities > Mbconnectline > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-15 CVE-2024-45274 Missing Authentication for Critical Function vulnerability in multiple products
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
network
low complexity
mbconnectline helmholz CWE-306
critical
9.8
2024-10-15 CVE-2024-45275 Use of Hard-coded Credentials vulnerability in multiple products
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
network
low complexity
mbconnectline helmholz CWE-798
critical
9.8
2021-08-02 CVE-2021-33527 Improper Input Validation vulnerability in Mbconnectline Mbdialup 3.9R0.0
In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input.
network
low complexity
mbconnectline CWE-20
critical
10.0
2020-04-14 CVE-2020-10383 Unspecified vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0.
network
low complexity
mbconnectline
critical
9.8