VYPR
High severity7.2NVD Advisory· Published Jul 21, 2025· Updated Jun 17, 2026

CVE-2025-41674

CVE-2025-41674

Description

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*
    Range: <2.3.3
  • Helmholz/REX 100v5
    Range: 0.0.0
  • MB connect line/mbNET.miniv5
    Range: 0.0.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.