CVE-2025-3091: Helmholz MYREX24

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.

Affected products

  • Helmholz MYREX24: before 2.18.0 (fixed in 2.18.0); before 2.16.5 (fixed in 2.16.5)
  • Helmholz MYREX24.VIRTUAL: before 2.18.0 (fixed in 2.18.0); before 2.16.5 (fixed in 2.16.5)
  • Mb Connect Line MBCONNECT24: before 2.16.5 (fixed in 2.16.5)
  • Mb Connect Line MYMBCONNECT24: before 2.18.0 (fixed in 2.18.0); before 2.16.5 (fixed in 2.16.5)

Published 2025-06-24. Last modified 2026-06-17.