CVE 7.2 HIGH

Remote Command Injection in diagnostic Action Due to Improper Input Neutralization_CVE-2025-41674

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.

Basic Information

ID CVE-2025-41674
Source CERTVDE
Published Jul 21, 2025 at 09:29
Modified Jul 21, 2025 at 17:05

Affected Product

Vendor MB connect line
Product mbNET.mini
Version 0.0.0
Affected Versions MB connect line mbNET.mini 0.0.0
Helmholz REX 100 0.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.