Description
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Published: 2026-05-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated SQL Injection vulnerability exists in the system_tag view of Helmholz and MB Connect Line devices. The flaw stems from insufficient neutralization of special characters within a SQL SELECT statement. A low‑privileged remote attacker can craft an input that manipulates the query, allowing them to read data beyond what the application should expose, resulting in a total loss of confidentiality.

Affected Systems

Vendors affected include Helmholz, with products myREX24V2 and myREX24V2.virtual, and MB Connect Line, with products mbCONNECT24 and mymbCONNECT24. All devices running software version 2.20.0 are vulnerable. The issue is present in both the operating system and application layers of these versions.

Risk and Exploitability

With a CVSS score of 7.1, the flaw is considered high severity. No EPSS data is available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is remote, requiring the attacker to have network access to the device and be able to send crafted requests to the system_tag endpoint. Successful exploitation can expose sensitive configuration and operational data, compromising confidentiality.

Generated by OpenCVE AI on May 27, 2026 at 10:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch that sanitizes input for the system_tag view.
  • If a patch is not yet available, restrict or disable external access to the system_tag endpoint or enforce strict authentication.
  • Implement input validation and parameterized queries in the application layer to prevent future injection.
  • Deploy a web application firewall rule set that blocks suspicious SQL patterns targeting the system_tag view.
  • Monitor device logs for anomalous SQL activity and review access controls regularly.

Generated by OpenCVE AI on May 27, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Title Authenticated SQLi in system_tag view
First Time appeared Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
Weaknesses CWE-89
CPEs cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:*
Vendors & Products Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Helmholz Myrex24v2 Myrex24v2.virtual Myrex24v2virtual
Mb Connect Line Mbconnect24 Mymbconnect24
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-27T11:55:30.441Z

Reserved: 2026-04-15T09:33:02.614Z

Link: CVE-2026-40847

cve-icon Vulnrichment

Updated: 2026-05-27T11:55:24.253Z

cve-icon NVD

Status : Deferred

Published: 2026-05-27T09:16:31.103

Modified: 2026-05-27T14:53:22.863

Link: CVE-2026-40847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T11:15:18Z

Weaknesses