Mbnet.mini Firmware
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45275 | Cri | 0.64 | 9.8 | 0.01 | Oct 15, 2024 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | ||
| CVE-2024-45274 | Cri | 0.64 | 9.8 | 0.02 | Oct 15, 2024 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | ||
| CVE-2024-45273 | Hig | 0.55 | 8.4 | 0.00 | Oct 15, 2024 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | ||
| CVE-2024-45271 | Hig | 0.55 | 8.4 | 0.00 | Oct 15, 2024 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | ||
| CVE-2024-45276 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2024 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | ||
| CVE-2025-41675 | Hig | 0.47 | 7.2 | 0.01 | Jul 21, 2025 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. | ||
| CVE-2025-41674 | Hig | 0.47 | 7.2 | 0.01 | Jul 21, 2025 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. | ||
| CVE-2025-41673 | Hig | 0.47 | 7.2 | 0.01 | Jul 21, 2025 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. | ||
| CVE-2025-41678 | Med | 0.42 | 6.5 | 0.01 | Jul 21, 2025 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. | ||
| CVE-2025-41679 | Med | 0.35 | 5.3 | 0.01 | Jul 21, 2025 | An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. | ||
| CVE-2025-41677 | Med | 0.32 | 4.9 | 0.01 | Jul 21, 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. | ||
| CVE-2025-41676 | Med | 0.32 | 4.9 | 0.01 | Jul 21, 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. | ||
| CVE-2025-41681 | Med | 0.31 | 4.8 | 0.00 | Jul 21, 2025 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. |
- risk 0.64cvss 9.8epss 0.01
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
- risk 0.64cvss 9.8epss 0.02
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
- risk 0.47cvss 7.2epss 0.01
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.
- risk 0.47cvss 7.2epss 0.01
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.
- risk 0.47cvss 7.2epss 0.01
A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command.
- risk 0.42cvss 6.5epss 0.01
A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.
- risk 0.35cvss 5.3epss 0.01
An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service.
- risk 0.32cvss 4.9epss 0.01
A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession.
- risk 0.32cvss 4.9epss 0.01
A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession.
- risk 0.31cvss 4.8epss 0.00
A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content.