CVE-2026-40851: Helmholz REX100
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
Affected products
- Helmholz REX100: from 0.0.0, up to and including 3.0.2; version 3.0.2 only
- Helmholz REX200/250: from 0.0.0, up to and including 8.4.4; version 8.4.4 only
- Mb Connect Line Mbnet.mini: from 0.0.0, up to and including 3.0.2; version 3.0.2 only
- Mb Connect Line Mbnet/mbnet.rokey: from 0.0.0, up to and including 8.4.4; version 8.4.4 only
Published 2026-05-27. Last modified 2026-06-17.