Impact
The vulnerability is a classic SQL injection flaw (CWE‑89) that occurs when user supplied input is incorporated into an SQL command without proper neutralization. An attacker who can supply crafted input to the vulnerable interface of Adam Retail Automation Ltd.'s MobilMen 20T can inject arbitrary SQL statements into the underlying database. This permits reading, modifying, or deleting records, thereby compromising the confidentiality, integrity, and potential availability of sales, inventory, and customer data.
Affected Systems
All releases of Adam Retail Automation Ltd.'s MobilMen 20T from version 3 through 10072026 are affected. No public patch or guidance from the vendor has been released; the vendor was contacted early about the disclosure but did not respond.
Risk and Exploitability
The CVSS score of 9.8 and EPSS score is reported as < 1 %, and the flaw is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been observed to date. The likely attack vector is remote network access to exposed input points, inferred from the nature of SQL injection vulnerabilities and the absence of input sanitization in triggered via a remote interface and the vendor has yet to supply a fix, the potential for exploitation remains significant for impacted users who cannot mitigate the issue through other means.
OpenCVE Enrichment