CVE-2025-41678: SQL Injection via POST Requests Allowing Configuration Database Manipulation
Published Jul 21, 2025
·Updated
A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.
Affected Software
2 affected components
All of the following
Mbconnectline Mbnet.mini Firmware<2.3.3
Mbconnectline Mbnet.mini
Event History
Jul 21, 2025
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41678?
CVE-2025-41678 is a high severity vulnerability due to its potential for remote exploitation by privileged attackers.
2
How can CVE-2025-41678 be mitigated?
To mitigate CVE-2025-41678, it is recommended to apply security patches and updates for the affected Mbconnectline Mbnet.mini firmware.
3
What can an attacker potentially do with CVE-2025-41678?
An attacker can alter the configuration database via malicious POST requests due to improper SQL statement handling.
4
Which versions of the Mbnet.mini firmware are affected by CVE-2025-41678?
CVE-2025-41678 affects Mbnet.mini firmware versions prior to 2.3.3.
5
Is there a known workaround for CVE-2025-41678?
There are no known workarounds for CVE-2025-41678; updating to the latest firmware version is highly recommended.