Impact
The vulnerability is an unauthenticated SQL injection in the getProjectTags function that can be triggered by a low‑privileged attacker. Improper neutralization of special characters allows arbitrary SELECT requests against the database, potentially exposing all data owned by the application. The impact described in the advisory is a total loss of confidentiality, with no indication of code execution or denial of service.
Affected Systems
Vulnerable products are Helmholz myREX24V2 and its virtual form, as well as MB Connect Line mbCONNECT24 and mymbCONNECT24. The affected firmware or software releases are version 2.20.0 for each product family.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Since the attack is remote and does not require full authentication, the likelihood of exploitation depends on the exposure of the vulnerable endpoint; attackers need network access to the target system and the ability to send crafted requests to the getProjectTags API.
OpenCVE Enrichment