Impact
The vulnerability resides in the VerifyCreateLicences function and allows a low‑privileged remote attacker to inject malicious SQL into an otherwise unauthenticated SELECT statement. This results in an unauthorized extraction of database contents, causing a total loss of confidentiality. The weakness is a classic input validation flaw described by CWE‑89.
Affected Systems
The affected products are Helmholz myREX24V2, both the physical and virtual editions, and MB Connect Line mbCONNECT24 / mymbCONNECT24, all running version 2.20.0. The issue is present across the listed products, but no patched version is specified in the advisory.
Risk and Exploitability
The CVSS score of 7.1 reflects a high‑severity risk, with an undisclosed EPSS and no current listing in the CISA KEV catalog. Because the flaw is remote and does not require authentication, the attack surface is considerable. Attackers can leverage it to read sensitive data with relatively low effort, presenting a significant threat to confidentiality.
OpenCVE Enrichment