High Privilege RCE via LUA Sandbox Escape

CVE Details

Basic Information

Title High Privilege RCE via LUA Sandbox Escape
Type cve
Published 2025-07-31T10:02:49.655Z
Modified 2025-07-31T10:02:49.655Z

Product Information

Vendor MB connect line
Product mbNET HW1
Version 0.0.0

CVSS Information

Base Score 7.2 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

  • MB connect line mbNET HW1 0.0.0
  • MB connect line mbNET/mbNET.rokey 0.0.0
  • Helmholz REX 300 0.0.0
  • Helmholz REX 200/250 0.0.0

Additional Information

CWE List CWE-653
Source CERTVDE

Description

A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.