Description
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Published: 2026-05-27
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated SQL Injection flaw in the DevSerialReset function allows a high‑privileged remote attacker to inject special characters into a SELECT statement. The vulnerability arises from inadequate neutralization of input elements, potentially exposing all data accessed by the function. The effect is a total loss of confidentiality for the affected databases.

Affected Systems

Helmholz myREX24V2 (including the virtual edition) and MB connect line mbCONNECT24 in both standard and mymbCONNECT24 variants are affected. All affected versions are the 2.20.0 release of the respective firmware.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers are presumed to gain remote network access to the product and can exploit the flaw when the DevSerialReset function is invoked with crafted input. Because the vulnerability requires high privilege, the attack surface is limited to authenticated users who have administrative rights on the devices. Nevertheless, the potential data breach warrants prioritised mitigation.

Generated by OpenCVE AI on May 27, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official firmware patch released by Helmholz and MB connect line that neutralizes input in the DevSerialReset function.
  • Disable or restrict remote access to the DevSerialReset functionality or limit it to trusted administrative accounts.
  • Segregate these devices within a separate network segment and enforce strict access controls to reduce the potential impact of a data breach.

Generated by OpenCVE AI on May 27, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 08:00:00 +0000

Type Values Removed Values Added
Description A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Title Authenticated SQLi in DevSerialReset function
First Time appeared Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
Weaknesses CWE-89
CPEs cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:*
Vendors & Products Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Helmholz Myrex24v2 Myrex24v2.virtual Myrex24v2virtual
Mb Connect Line Mbconnect24 Mymbconnect24
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-27T12:01:20.461Z

Reserved: 2026-04-15T09:33:02.611Z

Link: CVE-2026-40822

cve-icon Vulnrichment

Updated: 2026-05-27T12:01:15.379Z

cve-icon NVD

Status : Received

Published: 2026-05-27T08:16:42.853

Modified: 2026-05-27T08:16:42.853

Link: CVE-2026-40822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T12:15:05Z

Weaknesses