CVE-2025-41676: Resource Exhaustion via POST Requests to send-sms Action
Published Jul 21, 2025
·Updated
A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession.
Affected Software
2 affected components
All of the following
Mbconnectline Mbnet.mini Firmware<2.3.3
Mbconnectline Mbnet.mini
Event History
Jul 21, 2025
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41676?
CVE-2025-41676 has a high severity rating due to its potential for remote exploitation.
2
How does CVE-2025-41676 exploit system resources?
CVE-2025-41676 can exhaust critical system resources through specifically crafted POST requests sent in rapid succession.
3
Which software versions are affected by CVE-2025-41676?
CVE-2025-41676 affects versions of the Mbconnectline Mbnet.mini firmware up to but not including 2.3.3.
4
Who is at risk from CVE-2025-41676?
Any user or organization using vulnerable versions of Mbconnectline Mbnet.mini firmware is at risk from CVE-2025-41676.
5
What can be done to mitigate CVE-2025-41676?
To mitigate CVE-2025-41676, users should update the Mbconnectline Mbnet.mini firmware to version 2.3.3 or higher.