Impact
An endpoint named getDevicegroups is vulnerable to SQL Injection due to inadequate neutralization of special characters in a SELECT query. The flaw allows a low privileged remote attacker to execute arbitrary SQL code, leading to a complete compromise of data confidentiality. Based on the description, it is inferred that authentication is not required to trigger the attack. The vulnerability is classified as CWE‑89.
Affected Systems
Affected vendor products include Helmholz myREX24V2 and its virtual edition, as well as MB Connect Line mbCONNECT24 and mymbCONNECT24. The firmware release impacted is 2.20.0 for all listed products; users running these devices should verify that they are operating on this version or earlier, as the issue has been identified in that code base.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. EPSS data is unavailable, and the vulnerability is not listed in KEV, suggesting no widespread exploitation yet. Nonetheless, an attacker with low privileges can remotely exploit the flaw if the server is reachable from the network or the internet, and the potential for total loss of data confidentiality makes it a high priority for administrators.
OpenCVE Enrichment