Impact
The attack permitted a remote entity to inject SQL into the DevSerialReset function because special characters were not properly escaped. This flaw exposes the entire database to reading and allows changes to a non‑critical table, violating confidentiality and partially compromising integrity in accordance with CWE-89.
Affected Systems
The vulnerability affects Helmholz myREX24V2 and its virtual variant, as well as MB connect line products mbCONNECT24 and mymbCONNECT24, all released with firmware version 2.20.0. Users of these systems run the compromised application and are consequently exposed to data leakage and alteration.
Risk and Exploitability
With a CVSS score of 7.0 the flaw poses a moderate to high risk. Exploitation appears to be possible remotely without authentication, as the function is reachable over the network. The EPSS score is unavailable, and the issue is not catalogued in CISA KEV, but the potential for loss of confidential information warrants immediate remediation.
OpenCVE Enrichment