CVE-2026-33613: MB connect line mbCONNECT24 vulnerable to RCE in generateSrpArray
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data to the user table.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33613?
CVE-2026-33613 is rated as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-33613?
To fix CVE-2026-33613, update to the latest version of mbCONNECT24 beyond 2.19.4.
What types of attacks can exploit CVE-2026-33613?
CVE-2026-33613 can be exploited via remote code execution attacks using specially crafted OS commands.
Which software versions are affected by CVE-2026-33613?
CVE-2026-33613 affects versions of mbCONNECT24 and mymbCONNECT24 up to 2.19.4 inclusive.
What impact does CVE-2026-33613 have on affected systems?
Exploitation of CVE-2026-33613 can lead to full system compromise, allowing attackers to execute arbitrary commands.