Impact
The vulnerability resides in the DeleteSysLogEntry function where special characters are not properly neutralised in a SQL DELETE statement, creating an SQL Injection flaw. An attacker can execute arbitrary SQL commands, read data from the entire database, and delete entries in a non‑critical table, thereby causing a total loss of confidentiality and some loss of integrity.
Affected Systems
Helmholz products myREX24V2 (including the virtual variant) and MB connect line products mbCONNECT24 and mymbCONNECT24 are affected. Versions 2.20.0 of the operating systems for each product carry the flaw.
Risk and Exploitability
With remote attackers possessing high privileges, exploitation appears feasible if the DeleteSysLogEntry function is reachable. The CVSS score of 7.0 indicates a high severity. EPSS data is not available, and the vulnerability is not currently listed in CISA KEV, so the probability of exploitation is uncertain but could be significant in environments where the affected function is exposed to network traffic.
OpenCVE Enrichment