Impact
An unauthenticated remote attacker can exploit a SQL Injection vulnerability in the accountstatus view’s devices parameter, which is not properly sanitized in the SQL UPDATE statement. This flaw allows read access to the entire database and enables changes to non‑critical table rows, leading to total loss of confidentiality and some loss of integrity. The weakness is a classic SQL injection (CWE‑89).
Affected Systems
The affected products are Helmholz myREX24V2 and its virtual edition, as well as MB connect line mbCONNECT24 and mymbCONNECT24. All installations running version 2.20.0 are vulnerable, according to the provided CPE data.
Risk and Exploitability
The CVSS base score of 7 indicates a medium‑to‑high severity, and the absence of an EPSS score suggests that exploitation frequency is currently unknown. The vulnerability is remote, unauthenticated, and does not rely on user interaction. Because it can reveal all database contents and alter data, it represents a significant confidentiality breach and a potential integrity compromise. It is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment