CVE-2026-40832
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
- Vendor
- Helmholz, MB connect line, MB connect line, MB connect line, MB connect line, Helmholz, Helmholz, Helmholz
- Product
- myREX24V2.virtual, mbCONNECT24, mbCONNECT24, mymbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2, myREX24V2.virtual
- Provider severity
- HIGH, MEDIUM
- Conflicts
- 2