CVE-2025-41674: Mbconnectline Mbnet.mini Firmware

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.

Affected products

Published 2025-07-21. Last modified 2026-06-17.