CVE-2025-41674 HIGH

CVE-2025-41674: Remote Command Injection in diagnostic Action Due to Improper Input Neutralization

Vendor Mb Connect Line
Product mbNET.mini
Weakness CWE-78
Published July 21, 2025
Last update November 3, 2025

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.

Key dates

02Disclosure timeline

July 21, 2025 CVE published
November 3, 2025 Record updated