Impact
An unauthenticated SQL Injection vulnerability exists in the system_tag view of Helmholz and MB Connect Line devices. The flaw stems from insufficient neutralization of special characters within a SQL SELECT statement. A low‑privileged remote attacker can craft an input that manipulates the query, allowing them to read data beyond what the application should expose, resulting in a total loss of confidentiality.
Affected Systems
Vendors affected include Helmholz, with products myREX24V2 and myREX24V2.virtual, and MB Connect Line, with products mbCONNECT24 and mymbCONNECT24. All devices running software version 2.20.0 are vulnerable. The issue is present in both the operating system and application layers of these versions.
Risk and Exploitability
With a CVSS score of 7.1, the flaw is considered high severity. No EPSS data is available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is remote, requiring the attacker to have network access to the device and be able to send crafted requests to the system_tag endpoint. Successful exploitation can expose sensitive configuration and operational data, compromising confidentiality.
OpenCVE Enrichment