Impact
An unauthenticated remote attacker can inject arbitrary SQL commands through the _mb24confi_getDevice function, because special characters are not properly neutralized in a SELECT statement. This flaw allows the attacker to read or manipulate database contents, resulting in a complete loss of confidentiality for sensitive information stored by the device.
Affected Systems
Affected products include Helmholz myREX24V2 and its virtual variant, both running version 2.20.0, as well as MB connect line mbCONNECT24 and mymbCONNECT24, also at software revision 2.20.0. These systems are exposed to the same unauthenticated SQL injection vulnerability.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely without authentication, leveraging the SQL injection to access privileged data.
OpenCVE Enrichment