Impact
The vulnerability is an unauthenticated SQL Injection found in the setinfo endpoint of MB connect line products. Improper neutralization of special elements in a SQL UPDATE command allows a remote attacker to manipulate the statement, potentially altering configuration data or deleting critical records. The consequence is a total loss of integrity and availability, exposing the database to unauthorized changes and disrupting service functionality.
Affected Systems
Affected systems include MB connect line:mbCONNECT24 and MB connect line:mymbCONNECT24. No specific version information was supplied in the advisories; administrators should verify whether their deployed versions are susceptible based on the product family.
Risk and Exploitability
The CVSS score of 9.1 indicates a severe risk, and the vulnerability is exploitable remotely without authentication. Although EPSS data is not available, the lack of a KEV listing suggests that widespread exploitation may not yet be occurring, but the high severity warrants immediate attention. The likely attack vector is a remote, unauthenticated request to the setinfo endpoint, after which the attacker can inject arbitrary SQL statements to compromise data integrity and availability.
OpenCVE Enrichment