<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_helmholzgmbhcokg/10</id>
  <title>Most recent entries from csaf_helmholzgmbhcokg</title>
  <updated>2026-10-06T18:55:01.451207+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-057</id>
    <title>VDE-2021-057 — Helmholz: Privilege Escalation in shDialup (Update A)</title>
    <updated>2025-05-14T13:00:15+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In MB connect line mbDIALUP versions &lt;= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service. In MB connect line mbDIALUP versions &lt;= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-057"/>
    <published>2021-03-28T13:03:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-058</id>
    <title>VDE-2021-058 — Helmholz: Remote user enumeration in myREX24/myREX24-virtual</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-058"/>
    <published>2021-12-08T13:04:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-039</id>
    <title>VDE-2022-039 — Helmholz: Multiple vulnerabilites in myREX24 and myREX24.virtual</title>
    <updated>2022-09-07T10:56:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been found in myREX24 and myREX24.virtual.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-039"/>
    <published>2022-09-07T10:56:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-017</id>
    <title>VDE-2022-017 — Helmholz: Unauthenticated user enumeration in myREX24 and myREX24.virtual</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-017"/>
    <published>2022-09-07T12:54:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-008</id>
    <title>VDE-2023-008 — Helmholz: Multiple vulnerabilites in myREX24 and myREX24.virtual</title>
    <updated>2023-05-15T12:06:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Two vulnerabilites have been discovered in myREX24 and myREX24.virtual in all versions through 2.13.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-008"/>
    <published>2023-05-15T12:06:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-029</id>
    <title>VDE-2023-029 — Helmholz: Cross-site Scripting vulnerability in REX 200/REX 250</title>
    <updated>2023-08-17T12:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A stored XXS vulnerability has been found in REX 200 and REX 250 in all versions before 7.3.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-029"/>
    <published>2023-08-17T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-043</id>
    <title>VDE-2023-043 — Helmholz: Vulnerability allows access to non-critical information in myREX24 and myREX24.virtual</title>
    <updated>2023-10-16T08:38:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the affected products allows an authenticated, low-privileged attacker to gain unauthorized read access to limited, non-critical device information. The issue arises from improper access validation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-043"/>
    <published>2023-10-16T08:38:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-032</id>
    <title>VDE-2024-032 — Helmholz: REX 100 vulnerable to OS command injection</title>
    <updated>2024-07-03T13:33:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>There exists a vulnerability in all REX 100 devices with firmware &lt;= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests.</p>
<p>Update: 03.07.2024 3:30pm 
In section Reported by Sebastian Dietz (CyberDanube) was added.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-032"/>
    <published>2024-07-03T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-044</id>
    <title>VDE-2024-044 — Helmholz: Multiple products are vulnerable to regreSSHion</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Helmholz products are vulnerable to a possible race condition vulnerability in OpenSSH named "regreSSHion".</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-044"/>
    <published>2024-07-31T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-066</id>
    <title>VDE-2024-066 — Helmholz: Multiple Vulnerabilities in Helmholz REX100 Product</title>
    <updated>2025-08-27T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been discovered in REX100 allowing for RCE or unauthorized file access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-066"/>
    <published>2024-10-15T08:00:00+00:00</published>
  </entry>
</feed>
