CVE-2026-32969
7.5MB connect line, Helmholz · mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
An unauthenticated blind SQL injection vulnerability in the userinfo endpoint allows remote attackers to compromise system confidentiality through improper neutralization of SQL commands.
Executive summary
Multiple industrial connectivity products from MB connect line and Helmholz are vulnerable to unauthenticated SQL injection, posing a critical risk to data confidentiality.
Vulnerability
This is a blind SQL injection vulnerability (CWE-89) affecting the userinfo endpoint. The vulnerability is exploitable by unauthenticated remote attackers who can inject malicious SQL commands to extract data from the backend database.
Business impact
The exploitation of this vulnerability allows for the unauthorized extraction of sensitive data, leading to a total loss of confidentiality. With a CVSS score of 7.5, this high-severity flaw in industrial connectivity infrastructure could lead to significant operational disruption and the exposure of proprietary or sensitive user information.
Remediation
Immediate Action: Consult the official VDE advisories (VDE-2026-024 and VDE-2026-025) to determine if a patched version beyond 2.19.3 is available and apply it immediately.
Proactive Monitoring: Implement strict database query logging and monitor for unusual query patterns or spikes in traffic to the userinfo endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeted at the affected endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for total loss of confidentiality in these critical industrial connectivity products, administrators must prioritize this vulnerability. If a vendor patch is not yet available, restrict network access to the affected devices to trusted sources only and monitor logs for signs of unauthorized database interaction until a permanent fix can be applied.
Sources
Originally found and disclosed by Moritz Abrell, Christian Zäske from SySS GmbH, per the CVE Program record.