CVE-2025-41688: Helmholz Rex 200/250

High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.

A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.

Affected products

  • Helmholz Rex 200/250: from 0.0.0, before 7.3.0 (fixed in 7.3.0)
  • Helmholz Rex 300: from 0.0.0, up to and including 5.1.11
  • Mb Connect Line Mbnet/mbnet.rokey: from 0.0.0, before 7.3.0 (fixed in 7.3.0)
  • Mb Connect Line Mbnet HW1: from 0.0.0, up to and including 5.1.11

Published 2025-07-31. Last modified 2026-06-17.