Impact
An unauthenticated SQL Injection flaw resides in the UpdateParam routine of the view.html.php module. The flaw permits a remote actor to inject arbitrary SQL into a UPDATE command, enabling readers of the entire database and writers of non‑critical rows. The consequence is a loss of database confidentiality and a partial breach of data integrity, which could undermine trust in system data.
Affected Systems
Helmholz myREX24V2 (including virtual deployments) and MB Connect Line products mbCONNECT24 and mymbCONNECT24, all distributed in version 2.20.0, are susceptible according to the CPE references. The vulnerability appears in the embedded web interface exposed by these firmware releases.
Risk and Exploitability
The CVSS score of 7.0 signals a medium severity vulnerability that can be exploited remotely without user interaction. Because the flaw bypasses authentication checks, there is no prerequisite for valid credentials. While an EPSS score is not available, the existence of the CVE and lack of patching in the described firmware suggest a realistic exploitation potential. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment