Unrated severityNVD Advisory· Published Mar 23, 2026· Updated Mar 23, 2026
Unauthenticated RCE in com_mb24sysapi
CVE-2026-32968
Description
Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.
Affected products
4- Range: 0.0.0
- Helmholz/myREX24V2v5Range: 0.0.0
- Helmholz/myREX24V2.virtualv5Range: 0.0.0
- MB connect line/MB connect line mbCONNECT24v5Range: 0.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.