CVE-2024-5672

HIGH

Helmholz REX 100 and Red Lion Europe mbNET.mini <= 2.2.11 - Command Injection

Title source: llm
STIX 2.1

Description

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

Scores

CVSS v3 7.2
EPSS 0.0122
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
Helmholz/REX 100 < 2.2.11
Red Lion Europe/mbNET.mini < 2.2.11
Published Jul 03, 2024
Tracked Since Feb 18, 2026