CVE-2020-35557: Helmholz MYREX24
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.
Affected products
- Helmholz MYREX24: up to and including 2.11.2
- Helmholz MYREX24.VIRTUAL: up to and including 2.11.2
- Mbconnectline MBCONNECT24: up to and including 2.11.2
- Mbconnectline MYMBCONNECT24: up to and including 2.11.2
Published 2021-02-16. Last modified 2026-06-17.