CVE-2025-41673: Remote Command Injection in send_sms Action Due to Improper Input Neutralization
Published Jul 21, 2025
·Updated
A high privileged remote attacker can execute arbitrary system commands via POST requests in the sendsms action due to improper neutralization of special elements used in an OS command.
Affected Software
2 affected components
All of the following
Mbconnectline Mbnet.mini Firmware<2.3.3
Mbconnectline Mbnet.mini
Event History
Jul 21, 2025
CVE Published
via MITRE·09:29 AM
Data Sourced
via MITRE·09:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41673?
CVE-2025-41673 is classified as a high severity vulnerability.
2
How do I fix CVE-2025-41673?
To fix CVE-2025-41673, update the firmware of the Mbnet.mini device to version 2.3.3 or later.
3
What type of attack does CVE-2025-41673 allow?
CVE-2025-41673 allows high privileged remote attackers to execute arbitrary system commands via POST requests.
4
What software is affected by CVE-2025-41673?
CVE-2025-41673 affects the Mbconnectline Mbnet.mini Firmware versions prior to 2.3.3.
5
Is there a known workaround for CVE-2025-41673?
Currently, there is no known workaround for CVE-2025-41673 other than updating the firmware.