{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"Marcel Rick-Cen","summary":"reporting"}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"High"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"An authenticated remote attacker can exploit an undocumented method to escape the LUA sandbox in mbNET devices, enabling the execution of arbitrary operating system commands and leading to full system compromise.","title":"Summary"},{"category":"description","text":"This vulnerability allows an authenticated remote attacker to fully compromise the system by executing arbitrary OS commands.","title":"Impact"},{"category":"description","text":"Update mbNET/mbNET.rokey to at least version 7.3.0\\\n**Note**: mbNET HW1 is EOL and will not receive any further updates.","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"security-team@mbconnectline.de","name":"MB connect line GmbH","namespace":"https://mbconnectline.com"},"references":[{"category":"external","summary":"Product security incident reports","url":"https://mbconnectline.com/security-advice"},{"category":"external","summary":"CERT@VDE Security Advisories for MB connect line","url":"https://certvde.com/en/advisories/vendor/mbconnectline"},{"category":"self","summary":"VDE-2025-065: MB connect line: Sandbox escape in mbNET's LUA interpreter - HTML","url":"https://certvde.com/en/advisories/VDE-2025-065"},{"category":"self","summary":"VDE-2025-065: MB connect line: Sandbox escape in mbNET's LUA interpreter - CSAF","url":"https://mbconnectline.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-065.json"}],"title":"MB connect line: Sandbox escape in mbNET's LUA interpreter","tracking":{"aliases":["VDE-2025-065"],"current_release_date":"2025-07-31T10:00:00.000Z","generator":{"date":"2025-07-24T10:26:45.170Z","engine":{"name":"Secvisogram","version":"2.5.30"}},"id":"VDE-2025-065","initial_release_date":"2025-07-31T10:00:00.000Z","revision_history":[{"date":"2025-07-31T10:00:00.000Z","number":"1","summary":"Initial revision."}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"mbNET HW1","product":{"name":"MB connect line mbNET HW1","product_id":"CSAFPID-11002"}},{"category":"product_name","name":"mbNET/mbNET.rokey","product":{"name":"MB connect line mbNET/mbNET.rokey","product_id":"CSAFPID-11003"}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<=5.1.11","product":{"name":"Firmware <=5.1.11","product_id":"CSAFPID-21002"}},{"category":"product_version_range","name":"<7.3.0","product":{"name":"Firmware <7.3.0","product_id":"CSAFPID-21003"}},{"category":"product_version_range","name":">=7.3.0","product":{"name":"Firmware >=7.3.0","product_id":"CSAFPID-22002"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"MB connect line"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31003","CSAFPID-31004"],"summary":"Affected products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <=5.1.11 installed on MB connect line mbNET HW1","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware <7.3.0 installed on MB connect line mbNET/mbNET.rokey","product_id":"CSAFPID-31004"},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware >=7.3.0 installed on MB connect line mbNET/mbNET.rokey","product_id":"CSAFPID-32002"},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11003"}]},"vulnerabilities":[{"cve":"CVE-2025-41688","cwe":{"id":"CWE-653","name":"Improper Isolation or Compartmentalization"},"notes":[{"audience":"all","category":"description","text":"A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32002"],"known_affected":["CSAFPID-31003","CSAFPID-31004"]},"remediations":[{"category":"vendor_fix","details":"Update mbNET/mbNET.rokey to at least version 7.3.0\\\n**Note**: mbNET HW1 is EOL and will not receive any further updates.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.2,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":7.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31003","CSAFPID-31004"]}],"title":"CVE-2025-41688"}]}