Description
An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elements in an OS command. This can result in a total loss of confidentiality, availability and integrity.
Published: 2026-07-20
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated OS command injection flaw exists in the system_certificates view, allowing a high‑privileged attacker to inject and execute arbitrary operating‑system commands. The lack of proper neutralization of special elements in the OS command permits the attacker to gain full control over the affected device, leading to a total loss of confidentiality, integrity, and availability. The weakness is identified as CWE‑78.

Affected Systems

Helmholz product myREX24V2, including its virtual variant, runs firmware 2.20.0. MB connect line products mbCONNECT24 and mymbCONNECT24 also run firmware 2.20.0 and are affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, yet the flaw only requires authentication and high privileged rights to be exploited. Because the vulnerability permits OS command injection through the system_certificates interface, a remotely authenticated attacker can execute arbitrary commands on the device. The flaw is not listed in the CISA KEV catalog, yet its potential for full system compromise makes it a significant threat. The likely attack vector is an authenticated session to the system_certificates view where the attacker supplies input containing malicious command elements.

Generated by OpenCVE AI on July 30, 2026 at 19:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for Helmholz myREX24V2 and MB connect line devices that addresses the OS command injection in the system_certificates view.
  • Revoke or reduce elevated permissions for users accessing the system_certificates interface, limiting access to only essential administrators.
  • Implement input validation and sanitization for the system_certificates view to neutralize special characters, preventing OS command injection.

Generated by OpenCVE AI on July 30, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elements in an OS command. This can result in a total loss of confidentiality, availability and integrity.
Title Authenticated RCE in system_certificates view
First Time appeared Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
Weaknesses CWE-78
CPEs cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:*
Vendors & Products Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Helmholz Myrex24v2 Myrex24v2.virtual Myrex24v2virtual
Mb Connect Line Mbconnect24 Mymbconnect24
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-20T13:52:32.818Z

Reserved: 2026-07-02T07:14:32.098Z

Link: CVE-2026-14448

cve-icon Vulnrichment

Updated: 2026-07-20T13:52:24.578Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:45:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')