CVE-2026-40852: Helmholz REX100

High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.

A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability.

Affected products

  • Helmholz REX100: from 0.0.0, up to and including 3.0.2; version 3.0.2 only
  • Helmholz REX200/250: from 0.0.0, up to and including 8.4.4; version 8.4.4 only
  • Mb Connect Line Mbnet.mini: from 0.0.0, up to and including 3.0.2; version 3.0.2 only
  • Mb Connect Line Mbnet/mbnet.rokey: from 0.0.0, up to and including 8.4.4; version 8.4.4 only

Published 2026-05-27. Last modified 2026-06-17.