Summary
There is a vulnerability in mbCONNECT24/mymbCONNECT24 that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.
Impact
CVE-2026-10521 allows an authenticated remote attacker to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| MB connect line mbCONNECT24 | Firmware <2.20.2, Firmware 2.20.1 | |
| mymbCONNECT24 | Firmware <2.20.2, Firmware 2.20.1 |
Vulnerabilities
Expand / Collapse allAn authenticated remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.
Remediation
Update the mbCONNECT24/mymbCONNECT24 instance to version 2.20.2.
Acknowledgments
MB connect line GmbH thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 06/23/2026 13:00 | Initial revision. |