Impact
An unauthenticated SQL injection in the devices_configuration view allows a low‑privileged remote attacker to insert malicious SQL because special characters are not properly neutralized in a SELECT command, which can result in full disclosure of database contents and loss of confidentiality.
Affected Systems
Affected products include Helmholz myREX24V2 and its virtual edition, as well as MB Connect Line's mbCONNECT24 and mymbCONNECT24, all released with firmware version 2.20.0; the vulnerability resides in the devices_configuration view of these devices.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity potential. Although no EPSS score or KEV listing is available, the vulnerability’s nature—an unauthenticated SQLi that bypasses input sanitization—implies that exploitation could be performed over the network, allowing attackers to read sensitive configuration and user data without prior authentication.
OpenCVE Enrichment