CVE-2025-3092: Helmholz MYREX24

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.

Affected products

  • Helmholz MYREX24: before 2.18.0 (fixed in 2.18.0); before 2.16.5 (fixed in 2.16.5)
  • Helmholz MYREX24.VIRTUAL: before 2.18.0 (fixed in 2.18.0); before 2.16.5 (fixed in 2.16.5)
  • Mb Connect Line MBCONNECT24: before 2.16.5 (fixed in 2.16.5)
  • Mb Connect Line MYMBCONNECT24: before 2.18.0 (fixed in 2.18.0); before 2.16.5 (fixed in 2.16.5)

Published 2025-06-24. Last modified 2026-06-17.