Impact
This vulnerability is an unauthenticated SQL injection in the getAlarmProfiles function caused by insufficient neutralization of special characters in a SQL SELECT statement. The flaw, classified as CWE-89, allows a remote attacker to read arbitrary data from the database, resulting in a total loss of confidentiality.
Affected Systems
Affected products are Helmholz myREX24V2 (virtual and non‑virtual editions) and MB connect line mbCONNECT24 and mymbCONNECT24. The reported vulnerability affects firmware version 2.20.0 for all listed products.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS is not available, so the current exploitation likelihood is unknown, but the vulnerability is unauthenticated and can be triggered remotely. It is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over the network, as the function is accessible without authentication.
OpenCVE Enrichment