A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-054/ |
|
History
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability. | |
| Title | Command injection via malicious configuration | |
| First Time appeared |
Helmholz
Helmholz rex100 Helmholz rex200 250 Mb Connect Line Mb Connect Line mbnet Mb Connect Line mbnet.mini Mb Connect Line mbnet Mbnet.rokey |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:helmholz:rex100:*:*:*:*:*:*:*:* cpe:2.3:a:helmholz:rex200_250:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mbnet.mini:*:*:*:*:*:*:*:* cpe:2.3:a:mb_connect_line:mbnet_mbnet.rokey:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:rex100:3.0.2:*:*:*:*:*:*:* cpe:2.3:o:helmholz:rex200_250:8.4.4:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mbnet.mini:3.0.2:*:*:*:*:*:*:* cpe:2.3:o:mb_connect_line:mbnet:8.4.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Helmholz
Helmholz rex100 Helmholz rex200 250 Mb Connect Line Mb Connect Line mbnet Mb Connect Line mbnet.mini Mb Connect Line mbnet Mbnet.rokey |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-27T08:06:36.875Z
Reserved: 2026-04-15T09:33:02.614Z
Link: CVE-2026-40852
No data.
Status : Received
Published: 2026-05-27T09:16:31.817
Modified: 2026-05-27T09:16:31.817
Link: CVE-2026-40852
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:45:32Z
Weaknesses