Impact
The flaw allows a remote attacker with minimal privileges to inject arbitrary SQL when viewing tags. Because the application fails to neutralize special characters in the SELECT statement, the attacker can extract all data stored in the database, resulting in a total loss of confidentiality.
Affected Systems
Helmholz myREX24V2 and its virtual variant, as well as MB Connect Line's mbCONNECT24 and mymbCONNECT24 products, are affected. The vulnerability exists in the 2.20.0 build of these products only.
Risk and Exploitability
The CVSS score of 7.1 denotes moderate‑to‑high risk. Based on the description, the likely attack vector is sending an HTTP request to the tag view endpoint; no authentication is required, although the attacker must have low‑privilege access to the web interface. EPSS is not available and the issue is not listed in CISA KEV, indicating limited current exploitation but still a significant threat.
OpenCVE Enrichment