Impact
The vulnerability resides in the getDeviceScalings function where an input parameter is incorporated into a SQL SELECT statement without proper neutralization, allowing a malicious actor to inject arbitrary SQL code. This facilitates the extraction of sensitive data from the underlying database, resulting in a complete loss of confidentiality for anything stored there.
Affected Systems
Affected products include Helmholz myREX24V2 (both virtual and physical editions) and MB Connect Line devices such as mbCONNECT24 and mymbCONNECT24, all running firmware version 2.20.0. The vulnerability is present in the database interaction layers of these appliances.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk with potential for unauthorized data disclosure, while the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. The description indicates that the flaw can be exploited by a low‑privileged remote attacker without prior authentication, suggesting a straightforward attack path by sending crafted requests to the getDeviceScalings endpoint and reading the returned data.
OpenCVE Enrichment