Impact
An unauthenticated SQL Injection flaw in the DevSerialReset function allows a high‑privileged remote attacker to inject special characters into a SELECT statement. The vulnerability arises from inadequate neutralization of input elements, potentially exposing all data accessed by the function. The effect is a total loss of confidentiality for the affected databases.
Affected Systems
Helmholz myREX24V2 (including the virtual edition) and MB connect line mbCONNECT24 in both standard and mymbCONNECT24 variants are affected. All affected versions are the 2.20.0 release of the respective firmware.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers are presumed to gain remote network access to the product and can exploit the flaw when the DevSerialReset function is invoked with crafted input. Because the vulnerability requires high privilege, the attack surface is limited to authenticated users who have administrative rights on the devices. Nevertheless, the potential data breach warrants prioritised mitigation.
OpenCVE Enrichment