A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest function due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-044/ |
|
History
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest function due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical table. This can result in a total loss of confidentiality and some loss of integrity. | |
| Title | Authenticated SQLi in _RemoveRequest function | |
| First Time appeared |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:* cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-27T07:53:12.337Z
Reserved: 2026-04-15T09:33:02.612Z
Link: CVE-2026-40827
No data.
Status : Received
Published: 2026-05-27T09:16:28.013
Modified: 2026-05-27T09:16:28.013
Link: CVE-2026-40827
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:30:28Z
Weaknesses