Executive brief
A vulnerability exists in mbCONNECT24 and myREX24V2 remote service platforms, which are used for industrial remote maintenance and data logging. An attacker with high-level administrative privileges can execute unauthorized system commands, potentially leading to a complete takeover of the server. This could result in the theft of sensitive industrial data, disruption of remote access services, or unauthorized changes to connected industrial equipment.
Technical details
This vulnerability is classified as an OS command injection (CWE-78) within the 'system_certificates' view of the affected platforms. The root cause is the improper neutralization of special elements in an OS command, allowing an attacker to append or inject malicious commands into system calls. Exploitation requires the attacker to have high-level administrative privileges (PR:H) and network access to the management interface. Successful exploitation grants the attacker arbitrary command execution with the privileges of the web service, potentially leading to full system compromise (total loss of confidentiality, integrity, and availability). The vulnerability affects firmware versions up to and including 2.20.0.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
- Helmholz myREX24V2 <= 2.20.0
- Helmholz myREX24V2.virtual <= 2.20.0
Timeline
- 2026-05-21: advisory: Initial advisory published by Helmholz (VDE-2026-058)
- 2026-05-27: advisory: Initial advisory published by MB connect line (VDE-2026-044)
- 2026-07-20: disclosed: CVE-2026-14448 published to the NVD dataset