CVE-2025-41677: Resource Exhaustion via POST Requests to send-mail Action
Published Jul 21, 2025
·Updated
A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession.
Affected Software
2 affected components
All of the following
Mbconnectline Mbnet.mini Firmware<2.3.3
Mbconnectline Mbnet.mini
Event History
Jul 21, 2025
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41677?
CVE-2025-41677 has been classified as a high severity vulnerability due to its potential to allow remote attackers to exhaust critical system resources.
2
How do I fix CVE-2025-41677?
To mitigate CVE-2025-41677, implement rate limiting or input validation to control the volume of POST requests allowed to the send-mail action.
3
Which software versions are affected by CVE-2025-41677?
CVE-2025-41677 affects versions of the Mbconnectline Mbnet.mini firmware up to version 2.3.3.
4
Can CVE-2025-41677 be exploited remotely?
Yes, CVE-2025-41677 can be exploited by a high privileged remote attacker through specifically crafted POST requests.
5
What systems are vulnerable to CVE-2025-41677?
CVE-2025-41677 impacts systems running the Mbconnectline Mbnet.mini firmware.