Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-45274

CVE-2024-45274: Mbconnectline Mbnet.mini Firmware RCE

CVE-2024-45274 is a remote code execution vulnerability in Mbconnectline Mbnet.mini Firmware that allows unauthenticated attackers to execute OS commands via UDP. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2024-45274 Overview

CVE-2024-45274 is a missing authentication vulnerability [CWE-306] affecting industrial remote access routers from MB connect line and Helmholz. An unauthenticated remote attacker can send crafted UDP packets to the device and execute arbitrary operating system commands. The flaw impacts the mbNET.mini and REX 100 device families, which are widely deployed for industrial remote maintenance and machine connectivity. Successful exploitation grants attackers complete control over the affected device with no credentials or user interaction required.

Critical Impact

Unauthenticated attackers on the network can execute arbitrary OS commands on affected industrial routers via UDP, leading to full device compromise and potential pivoting into operational technology (OT) networks.

Affected Products

  • MB connect line mbNET.mini firmware and hardware
  • Helmholz REX 100 firmware and hardware
  • All firmware versions prior to the vendor-supplied fix

Discovery Timeline

  • 2024-10-15 - CVE-2024-45274 published to the National Vulnerability Database (NVD)
  • 2025-11-03 - Last updated in NVD database

Technical Details for CVE-2024-45274

Vulnerability Analysis

The vulnerability stems from a UDP-accessible service on the affected devices that processes command input without verifying the identity of the sender. Because the device lacks any authentication check on this network-facing interface, any attacker capable of reaching the device on the affected UDP port can inject operating system commands. The commands execute in the context of the service handling UDP traffic, typically with elevated privileges on embedded Linux-based industrial routers.

The affected mbNET.mini and REX 100 devices are designed as secure remote access gateways into industrial environments. A compromised device therefore exposes the protected programmable logic controllers (PLCs), human-machine interfaces (HMIs), and other OT assets behind it. Attackers can use the foothold to disable security functions, capture VPN credentials, or relay attacks deeper into the plant network.

The issue is tracked under VDE Security Advisory VDE-2024-056, VDE Security Advisory VDE-2024-066, and SYSS Security Advisory SYSS-2024-063.

Root Cause

The root cause is missing authentication for a critical function [CWE-306]. A network service bound to a UDP port accepts and processes command-style input without validating the requester. There is no shared secret, certificate, session token, or source restriction enforcing access control on this interface.

Attack Vector

The attack vector is network-based and connectionless. An attacker crafts a UDP datagram containing the OS command payload and sends it to the affected port on the device. Because UDP requires no handshake, the attacker can spoof source addresses and operate from anywhere with routable access to the device. Devices reachable through misconfigured firewall rules, exposed VPN segments, or directly on the public internet are at the highest risk. See the Full Disclosure post from July 2025 for additional context on the disclosure.

No verified proof-of-concept exploit code has been published. The vulnerability mechanism is described in prose by the referenced advisories rather than with public exploit artifacts.

Detection Methods for CVE-2024-45274

Indicators of Compromise

  • Unexpected UDP traffic toward mbNET.mini or REX 100 management ports from untrusted source addresses
  • New or modified processes on the device, unexpected outbound connections, or unauthorized configuration changes
  • Device log entries showing command execution events without an associated authenticated administrator session

Detection Strategies

  • Inspect network flow records for UDP traffic to affected devices originating outside the documented administrative network segments
  • Compare device firmware versions and configuration baselines against vendor-published fixed releases to identify exposed assets
  • Alert on any inbound UDP traffic to the affected routers from the internet or untrusted VLANs at perimeter and OT-DMZ firewalls

Monitoring Recommendations

  • Enable and forward device syslog to a centralized SIEM and monitor for command execution, configuration change, and reboot events
  • Apply network segmentation monitoring between IT and OT zones to detect lateral movement from a compromised gateway
  • Track outbound connections from mbNET.mini and REX 100 devices and flag any traffic to non-approved destinations

How to Mitigate CVE-2024-45274

Immediate Actions Required

  • Inventory all mbNET.mini and REX 100 devices and identify their network exposure, especially any with public-facing interfaces
  • Block inbound UDP traffic to affected devices from untrusted networks at the perimeter firewall until patches are applied
  • Apply the firmware update referenced in VDE-2024-056 and VDE-2024-066 as soon as it is available for your model
  • Rotate VPN credentials, certificates, and any shared secrets stored on devices that may have been exposed

Patch Information

MB connect line and Helmholz have published coordinated advisories through CERT@VDE. Refer to VDE Security Advisory VDE-2024-056 for mbNET.mini and VDE Security Advisory VDE-2024-066 for REX 100 for the fixed firmware versions and update procedures. Additional technical analysis is available in the SYSS-2024-063 advisory.

Workarounds

  • Restrict device management interfaces to a dedicated administrative VLAN and deny all other UDP traffic via ACLs
  • Place affected routers behind an upstream firewall that performs stateful filtering and source-address validation
  • Disable any unused remote-access services on the device and ensure VPN tunnels terminate only from trusted endpoints
  • Continuously monitor device logs and network telemetry for signs of unauthorized command execution until firmware is updated

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.