Remote Code Execution Vulnerability in VDE-2026 Software by CERTVDE
CVE-2026-33613
7.2HIGH
Key Information:
- Vendor
Mb Connect Line
- Status
- Vendor
- CVE Published:
- 2 April 2026
What is CVE-2026-33613?
A vulnerability exists in the VDE-2026 Software due to improper handling of special characters in OS command inputs within the generateSrpArray function. If exploited, a remote attacker who can manipulate the user table may gain the capability to execute arbitrary commands on the system, potentially leading to a full system compromise. Organizations using this software are advised to review their security posture and apply necessary mitigations.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.19.4
mymbCONNECT24 0.0.0 <= 2.19.4
