Impact
An unauthenticated remote attacker can perform a SQL injection in the Easy View component because special elements are not properly neutralized in a SQL SELECT command. This flaw corresponds to CWE‑89 and can lead to a total loss of confidentiality if exploited, as the attacker may read sensitive data from the database.
Affected Systems
The vulnerability affects Helmholz myREX24V2 and myREX24V2.virtual, as well as MB connect line mbCONNECT24 and mymbCONNECT24. The documented affected release is 2.20.0 for each product. If an organization runs any of these versions of the software, the environment is potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The attack vector is remote, and authentication is not required, allowing low‑privileged attackers to leverage the flaw. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread public exploitation is not yet confirmed. Nevertheless, the potential for full confidentiality compromise warrants immediate attention.
OpenCVE Enrichment