Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-044/ |
|
Wed, 27 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveDashboardLayout function due to improper neutralization of special elements in a SQL INSERT command allowing for reading the whole database and inserting entries into a non critical table. This can result in a total loss of confidentiality and some loss of integrity. | |
| Title | Authenticated SQLi in saveDashboardLayout function | |
| First Time appeared |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:* cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Helmholz
Helmholz myrex24v2 Helmholz myrex24v2.virtual Helmholz myrex24v2virtual Mb Connect Line Mb Connect Line mbconnect24 Mb Connect Line mymbconnect24 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-27T11:58:44.521Z
Reserved: 2026-04-15T09:33:02.612Z
Link: CVE-2026-40833
Updated: 2026-05-27T11:58:39.906Z
Status : Deferred
Published: 2026-05-27T09:16:28.950
Modified: 2026-06-17T10:45:44.090
Link: CVE-2026-40833
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:45:31Z