Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-044/ |
|
Wed, 27 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view devices parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity. | |
| Title | Authenticated SQLi in accountstatus view | |
| First Time appeared |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:* cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-27T12:00:37.390Z
Reserved: 2026-04-15T09:33:02.611Z
Link: CVE-2026-40825
Updated: 2026-05-27T12:00:32.731Z
Status : Deferred
Published: 2026-05-27T08:16:43.307
Modified: 2026-06-17T10:45:43.030
Link: CVE-2026-40825
No data.
OpenCVE Enrichment
Updated: 2026-05-27T11:00:12Z