A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php files UpdateParam function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-044/ |
|
History
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php files UpdateParam function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity. | |
| Title | Authenticated SQLi in UpdateParam function | |
| First Time appeared |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:* cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-27T07:54:13.439Z
Reserved: 2026-04-15T09:33:02.612Z
Link: CVE-2026-40830
No data.
Status : Received
Published: 2026-05-27T09:16:28.467
Modified: 2026-05-27T09:16:28.467
Link: CVE-2026-40830
No data.
OpenCVE Enrichment
Updated: 2026-05-27T11:15:18Z
Weaknesses