{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"names":["Sebastian Dietz"],"organization":"CyberDanube","summary":"coordination","urls":["https://cyberdanube.com/"]},{"names":["F. Bruckmoser","M. Eder","J. Heigl","M. Heudorn","G. Hofmarcher","M. Kadlec","M. Pristauz-Telsnigg","S. Resch","P. Schweinzer","M. Gschiel"],"organization":"St. Poelten UAS","summary":"reporting","urls":["https://fhstp.ac.at"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"Critical"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Multiple vulnerabilities in all REX 100 devices with firmware <= 2.3.2 that allow an attacker to gain full control over the device.","title":"Summary"},{"category":"description","text":"Full control over the device is possible in various ways. For details see CVE description.","title":"Impact"},{"category":"description","text":"Update to latest version: 2.3.3","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@helmholz.de","name":"Helmholz GmbH & Co. KG","namespace":"https://www.helmholz.de"},"references":[{"category":"external","summary":"CERT@VDE Security Advisories for Helmholz GmbH & Co. KG","url":"https://certvde.com/en/advisories/vendor/helmholz/"},{"category":"self","summary":"VDE-2025-059: Helmholz: Multiple vulnerabilities in REX 100 - HTML","url":"https://certvde.com/en/advisories/VDE-2025-059/"},{"category":"self","summary":"VDE-2025-059: Helmholz: Multiple vulnerabilities in REX 100 - CSAF","url":"https://helmholz.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-059.json"},{"category":"external","summary":"Helmholz PSIRT","url":"https://www.helmholz.de/service-support/service/security-psirt/"}],"title":"Helmholz: Multiple vulnerabilities in REX 100","tracking":{"aliases":["VDE-2025-059"],"current_release_date":"2025-07-21T10:00:00.000Z","generator":{"date":"2025-07-15T14:45:33.644Z","engine":{"name":"Secvisogram","version":"2.5.30"}},"id":"VDE-2025-059","initial_release_date":"2025-07-21T10:00:00.000Z","revision_history":[{"date":"2025-07-21T10:00:00.000Z","number":"1","summary":"Initial revision."}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"REX 100","product":{"name":"REX 100","product_id":"CSAFPID-11001"}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version","name":"2.3.3","product":{"name":"Firmware 2.3.3","product_id":"CSAFPID-22001"}},{"category":"product_version_range","name":"<2.3.3","product":{"name":"Firmware <2.3.3","product_id":"CSAFPID-21001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"MB connect line"}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <2.3.3 installed on REX 100","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-11001","relates_to_product_reference":"CSAFPID-21001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.3.3 installed on REX 100","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-11001","relates_to_product_reference":"CSAFPID-22001"}]},"vulnerabilities":[{"cve":"CVE-2025-41673","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"As this is an authenticated exploit, you can mitigate it by making sure that no malicious actor can login to a vulnerable device.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.2,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":7.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41673"},{"cve":"CVE-2025-41674","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"As this is an authenticated exploit, you can mitigate it by making sure that no malicious actor can login to a vulnerable device.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.2,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":7.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41674"},{"cve":"CVE-2025-41675","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"As this is an authenticated exploit, you can mitigate it by making sure that no malicious actor can login to a vulnerable device.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.2,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":7.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41675"},{"cve":"CVE-2025-41676","cwe":{"id":"CWE-400","name":"Uncontrolled Resource Consumption"},"notes":[{"category":"description","text":"A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"As this is an authenticated exploit, you can mitigate it by making sure that no malicious actor can login to a vulnerable device.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":4.9,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":4.9,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41676"},{"cve":"CVE-2025-41677","cwe":{"id":"CWE-400","name":"Uncontrolled Resource Consumption"},"notes":[{"category":"description","text":"A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"As this is an authenticated exploit, you can mitigate it by making sure that no malicious actor can login to a vulnerable device.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":4.9,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":4.9,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41677"},{"cve":"CVE-2025-41678","cwe":{"id":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"},"notes":[{"category":"description","text":"A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"As this is an authenticated exploit, you can mitigate it by making sure that no malicious actor can login to a vulnerable device.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":6.5,"environmentalSeverity":"MEDIUM","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":6.5,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41678"},{"cve":"CVE-2025-41679","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"notes":[{"category":"description","text":"An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]},{"category":"mitigation","details":"Enable \"Lock network configuration (Conftool)\" in device configuration (enabled by default after device comes online for the first time).","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41679"},{"cve":"CVE-2025-41681","cwe":{"id":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"},"notes":[{"category":"description","text":"A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-31002"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"As this is an authenticated exploit, you can mitigate it by making sure that no malicious actor can login to a vulnerable device.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"Update to latest version: 2.3.3","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":4.8,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","temporalScore":4.8,"temporalSeverity":"MEDIUM","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2025-41681"}]}