Impact
An authenticated OS command injection flaw exists in the system_certificates view, allowing a high‑privileged attacker to inject and execute arbitrary operating‑system commands. The lack of proper neutralization of special elements in the OS command permits the attacker to gain full control over the affected device, leading to a total loss of confidentiality, integrity, and availability. The weakness is identified as CWE‑78.
Affected Systems
Helmholz product myREX24V2, including its virtual variant, runs firmware 2.20.0. MB connect line products mbCONNECT24 and mymbCONNECT24 also run firmware 2.20.0 and are affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, yet the flaw only requires authentication and high privileged rights to be exploited. Because the vulnerability permits OS command injection through the system_certificates interface, a remotely authenticated attacker can execute arbitrary commands on the device. The flaw is not listed in the CISA KEV catalog, yet its potential for full system compromise makes it a significant threat. The likely attack vector is an authenticated session to the system_certificates view where the attacker supplies input containing malicious command elements.
OpenCVE Enrichment