CVE-2026-33613
HIGHMB connect line mbCONNECT24 vulnerable to RCE in generateSrpArray
Title source: cnaDescription
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data to the user table.
Scores
CVSS v3
7.2
EPSS
0.0013
EPSS Percentile
31.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (4)
MB connect line/mbCONNECT24
0.0.0 - 2.19.4
MB connect line/mymbCONNECT24
0.0.0 - 2.19.4
mbconnectline/mbconnect24
< 2.19.4
mbconnectline/mymbconnect24
< 2.19.4
Published
Apr 02, 2026
Tracked Since
Apr 02, 2026