<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_helmholzgmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:04:52 +0000</lastBuildDate>
    <item>
      <title>VDE-2021-057 — Helmholz: Privilege Escalation in shDialup (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-057</link>
      <description>&lt;p&gt;In MB connect line mbDIALUP versions &amp;lt;= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service. In MB connect line mbDIALUP versions &amp;lt;= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In MB connect line mbDIALUP versions &amp;lt;= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service. In MB connect line mbDIALUP versions &amp;lt;= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-057</guid>
      <pubDate>Sun, 28 Mar 2021 13:03:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-058 — Helmholz: Remote user enumeration in myREX24/myREX24-virtual</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-058</link>
      <description>&lt;p&gt;An unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-058</guid>
      <pubDate>Wed, 08 Dec 2021 13:04:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-039 — Helmholz: Multiple vulnerabilites in myREX24 and myREX24.virtual</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-039</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been found in myREX24 and myREX24.virtual.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been found in myREX24 and myREX24.virtual.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-039</guid>
      <pubDate>Wed, 07 Sep 2022 10:56:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-017 — Helmholz: Unauthenticated user enumeration in myREX24 and myREX24.virtual</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-017</link>
      <description>&lt;p&gt;A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-017</guid>
      <pubDate>Wed, 07 Sep 2022 12:54:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-008 — Helmholz: Multiple vulnerabilites in myREX24 and myREX24.virtual</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-008</link>
      <description>&lt;p&gt;Two vulnerabilites have been discovered in myREX24 and myREX24.virtual in all versions through 2.13.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Two vulnerabilites have been discovered in myREX24 and myREX24.virtual in all versions through 2.13.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-008</guid>
      <pubDate>Mon, 15 May 2023 12:06:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-029 — Helmholz: Cross-site Scripting vulnerability in REX 200/REX 250</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-029</link>
      <description>&lt;p&gt;A stored XXS vulnerability has been found in REX 200 and REX 250 in all versions before 7.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stored XXS vulnerability has been found in REX 200 and REX 250 in all versions before 7.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-029</guid>
      <pubDate>Thu, 17 Aug 2023 12:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-043 — Helmholz: Vulnerability allows access to non-critical information in myREX24 and myREX24.virtual</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-043</link>
      <description>&lt;p&gt;A vulnerability in the affected products allows an authenticated, low-privileged attacker to gain unauthorized read access to limited, non-critical device information. The issue arises from improper access validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the affected products allows an authenticated, low-privileged attacker to gain unauthorized read access to limited, non-critical device information. The issue arises from improper access validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-043</guid>
      <pubDate>Mon, 16 Oct 2023 08:38:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-032 — Helmholz: REX 100 vulnerable to OS command injection</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-032</link>
      <description>&lt;p&gt;There exists a vulnerability in all REX 100 devices with firmware &amp;lt;= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests.&lt;/p&gt;
&lt;p&gt;Update: 03.07.2024 3:30pm 
In section Reported by Sebastian Dietz (CyberDanube) was added.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There exists a vulnerability in all REX 100 devices with firmware &amp;lt;= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests.&lt;/p&gt;
&lt;p&gt;Update: 03.07.2024 3:30pm 
In section Reported by Sebastian Dietz (CyberDanube) was added.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-032</guid>
      <pubDate>Wed, 03 Jul 2024 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-044 — Helmholz: Multiple products are vulnerable to regreSSHion</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-044</link>
      <description>&lt;p&gt;Several Helmholz products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Helmholz products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-044</guid>
      <pubDate>Wed, 31 Jul 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-066 — Helmholz: Multiple Vulnerabilities in Helmholz REX100 Product</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-066</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been discovered in REX100 allowing for RCE or unauthorized file access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been discovered in REX100 allowing for RCE or unauthorized file access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-066</guid>
      <pubDate>Tue, 15 Oct 2024 08:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
