Summary
Two command injection vulnerabilities have been discovered in MB connect line mbNET/mbNET.rokey/mbNET.mini.
Impact
The vulnerabilities allow for command injection in mbNET/mbNET.rokey/mbNET.mini with varying prerequisites resulting in full system compromise.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| mbNET.mini | Firmware 3.0.2, Firmware <=3.0.2 | |
| mbNET/mbNET.rokey | Firmware <=8.4.4, Firmware 8.4.4 |
Vulnerabilities
Expand / Collapse allA low privileged local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
A high privileged attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
Remediation
Update:
- mbNET/mbNET.rokey: 8.4.5
- mbNET.mini: 3.0.3
Acknowledgments
MB connect line GmbH thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- Moritz Abrell, Christian Zäske from SySS GmbH for reporting (see https://www.syss.de )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 27.05.2026 13:00 | Initial revision. |