CVE-2026-40852: Helmholz REX100
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
Affected products
- Helmholz REX100: from 0.0.0, up to and including 3.0.2; version 3.0.2 only
- Helmholz REX200/250: from 0.0.0, up to and including 8.4.4; version 8.4.4 only
- Mb Connect Line Mbnet.mini: from 0.0.0, up to and including 3.0.2; version 3.0.2 only
- Mb Connect Line Mbnet/mbnet.rokey: from 0.0.0, up to and including 8.4.4; version 8.4.4 only
Published 2026-05-27. Last modified 2026-06-17.