{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"Marcel Rick-Cen","summary":"reporting"}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"High"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"An authenticated remote attacker can exploit an undocumented method to escape the LUA sandbox in REX200/250 devices, enabling the execution of arbitrary operating system commands and leading to full system compromise.","title":"Summary"},{"category":"description","text":"This vulnerability allows an authenticated remote attacker to fully compromise the system by executing arbitrary OS commands.","title":"Impact"},{"category":"description","text":"Update REX 200/250 to at least version 7.3.0\\\n**Note**: REX 300 is EOL and will not receive any further updates.","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@helmholz.de","name":"Helmholz GmbH & Co. KG","namespace":"https://www.helmholz.de"},"references":[{"category":"external","summary":"Product security incident reports","url":"https://www.helmholz.de/service-support/service/security-psirt"},{"category":"external","summary":"CERT@VDE Security Advisories for Helmholz","url":"https://certvde.com/en/advisories/vendor/helmholz"},{"category":"self","summary":"VDE-2025-069: Helmholz: Sandbox escape in REX200/250 LUA interpreter - HTML","url":"https://certvde.com/en/advisories/VDE-2025-065"},{"category":"self","summary":"VDE-2025-069: Helmholz: Sandbox escape in REX200/250 LUA interpreter - CSAF","url":"https://helmholz.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-069.json"}],"title":"Helmholz: Sandbox escape in REX200/250 LUA interpreter","tracking":{"aliases":["VDE-2025-069"],"current_release_date":"2025-07-31T10:00:00.000Z","generator":{"date":"2025-07-28T06:46:48.634Z","engine":{"name":"Secvisogram","version":"2.5.31"}},"id":"VDE-2025-069","initial_release_date":"2025-07-31T10:00:00.000Z","revision_history":[{"date":"2025-07-31T10:00:00.000Z","number":"1","summary":"Initial revision."}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"REX 300","product":{"name":"Helmholz REX 300","product_id":"CSAFPID-11002"}},{"category":"product_name","name":"REX 200/250","product":{"name":"Helmholz REX 200/250","product_id":"CSAFPID-11003"}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<=5.1.11","product":{"name":"Firmware <=5.1.11","product_id":"CSAFPID-21002"}},{"category":"product_version_range","name":"<7.3.0","product":{"name":"Firmware <7.3.0","product_id":"CSAFPID-21003"}},{"category":"product_version_range","name":">=7.3.0","product":{"name":"Firmware >=7.3.0","product_id":"CSAFPID-22002"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"MB connect line"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31003","CSAFPID-31004"],"summary":"Affected products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <=5.1.11 installed on Helmholz REX 300","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware <7.3.0 installed on Helmholz REX 200/250","product_id":"CSAFPID-31004"},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware >=7.3.0 installed on Helmholz REX 200/250","product_id":"CSAFPID-32002"},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11003"}]},"vulnerabilities":[{"cve":"CVE-2025-41688","cwe":{"id":"CWE-653","name":"Improper Isolation or Compartmentalization"},"notes":[{"audience":"all","category":"description","text":"A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32002"],"known_affected":["CSAFPID-31003","CSAFPID-31004"]},"remediations":[{"category":"vendor_fix","details":"Update REX 200/250 to at least version 7.3.0\\\n**Note**: REX 300 is EOL and will not receive any further updates.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.2,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":7.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31003","CSAFPID-31004"]}],"title":"CVE-2025-41688"}]}