Description
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Published: 2026-05-27
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated SQL Injection that occurs within the sync_data24 task because special characters are not properly neutralized in a SQL SELECT statement. An attacker who can reach the sync_data24 service does not need to authenticate, and can supply crafted input that is directly incorporated into the query, allowing the attacker to read arbitrary data from the database. The advisory states that this can lead to a total loss of confidentiality, meaning the attacker can acquire all data that the task has access to.

Affected Systems

Affected products are Helmholz myREX24V2, Helmholz myREX24V2 virtual, MB Connect Line mbCONNECT24, and MB Connect Line mymbCONNECT24. The CPE entries indicate that version 2.20.0 of each product is impacted. No other version information is provided in the advisory.

Risk and Exploitability

The CVSS score of 8.7 reflects high severity. The EPSS score is not available, so the probability of exploitation at the time of this analysis cannot be quantified from the data. The vulnerability is listed as not present in CISA KEV, but the lack of an EPSS entry does not preclude future exploitation. Attack execution requires network access to the sync_data24 endpoint and the ability to inject a payload; authentication is not required, so any system exposed to the network that hosts the task is a potential target.

Generated by OpenCVE AI on May 27, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all myREX24V2 and MB Connect Line devices to the latest firmware release that includes the SQL injection fix.
  • If a timely update is unavailable, disable the sync_data24 task or block its network access until a patch is applied.
  • Configure firewall or network segmentation policies to restrict access to the sync_data24 endpoint so that only trusted internal systems can invoke it.
  • Implement strict input validation or parameterized queries for the sync_data24 request to prevent injection attacks.

Generated by OpenCVE AI on May 27, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 08:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Title Unauthenticated SQLi in sync_data24 task
First Time appeared Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
Weaknesses CWE-89
CPEs cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:*
Vendors & Products Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Helmholz Myrex24v2 Myrex24v2.virtual Myrex24v2virtual
Mb Connect Line Mbconnect24 Mymbconnect24
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-27T07:49:14.497Z

Reserved: 2026-04-15T09:33:02.611Z

Link: CVE-2026-40819

cve-icon Vulnrichment

Updated: 2026-05-27T12:01:42.702Z

cve-icon NVD

Status : Received

Published: 2026-05-27T08:16:42.507

Modified: 2026-05-27T08:16:42.507

Link: CVE-2026-40819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T13:15:05Z

Weaknesses