CVE-2025-3091: MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24
Published Jun 24, 2025
·Updated
An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other users password.
Affected Software
2 affected components
MB connect line mbCONNECT24
MB connect line mymbCONNECT24
Event History
Jun 24, 2025
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3091?
CVE-2025-3091 is considered a low severity vulnerability.
2
How do I mitigate CVE-2025-3091?
To mitigate CVE-2025-3091, ensure that multi-factor authentication is properly implemented and that access rights are reviewed regularly.
3
Who is affected by CVE-2025-3091?
CVE-2025-3091 affects users of MB Connect Line mbCONNECT24 and mymbCONNECT24.
4
Can CVE-2025-3091 be exploited remotely?
Yes, CVE-2025-3091 can be exploited by a low privileged remote attacker.
5
What happens if CVE-2025-3091 is exploited?
If CVE-2025-3091 is exploited, an attacker can log in as another user without knowing their password.