Impact
The vulnerability is a SQL injection that allows a low privileged remote attacker to execute arbitrary SELECT commands against the database through the user_alarmprofile view. The lack of input sanitization means attackers can retrieve sensitive data, resulting in a total loss of confidentiality. This weakness is identified as CWE-89, indicating improper neutralization of special elements in SQL statements.
Affected Systems
The flaw applies to Helmholz myREX24V2 (both virtual and non‑virtual versions) and MB connect line devices mybCONNECT24 and mymbCONNECT24, all running firmware version 2.20.0.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting it may not yet be actively exploited, though the attack vector is remote and requires only low privileged access. Once authenticated or unauthenticated access to the web interface is possible, the exploit can be performed by sending a crafted SQL statement that is not properly parameterized. The attacker obtains sensitive data from the database, compromising confidentiality.
OpenCVE Enrichment