Impact
The vulnerability is an SQL injection flaw that allows an attacker to inject malicious commands into an SQL query. When the attack is successful, the injected statement can cause the underlying database engine to execute arbitrary SQL, and because the error message mentions Command Line Execution, the attacker can gain the ability to run operating‑system commands on the host. This compromises confidentiality, integrity, and availability by enabling full control over the affected machine.
Affected Systems
Trex Digital Smart Manufacturing Systems Inc. Trex MES is affected for all releases through 2026‑09‑29. No newer versions are known to fix the issue.
Risk and Exploitability
The CVSS base score is 9.8, indicating a critical level of risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is an SQL injection that can lead to command execution, the likely attack vector is via application input that is processed into an SQL statement. Attackers would need network access to the application, and the vulnerability may require authentication or privileged access depending on how the input is exposed. The combination of a very high CVSS score and the potential for remote code execution represents a significant threat to affected deployments.
OpenCVE Enrichment