Impact
Based on the CVE description, it is inferred that the vulnerability is an unauthenticated SQL Injection in the inmessage model of Helmholz myREX24V2 and MB connect line devices. Improper neutralization of special characters in a SQL DELETE statement allows a low‑privileged remote attacker to read the entire database and delete rows from a non‑critical table, resulting in total confidentiality loss and partial integrity compromise. This is a classic input validation flaw (CWE‑89).
Affected Systems
The affected products are Helmholz myREX24V2 and its virtual edition, and MB connect line mbCONNECT24 and mymbCONNECT24, all running version 2.20.0. The vulnerability is present in the inmessage model component of these systems.
Risk and Exploitability
Based on the data, the likely attack vector is a remote network-based attack: an attacker with network access to the inmessage endpoint can exploit the flaw to exfiltrate data or delete entries without authentication. The CVSS score of 7.1 marks the issue as high severity; the EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The lack of authentication requirement suggests a wide attack surface over the network.
OpenCVE Enrichment