CVE-2025-41688
HIGHMB connect line mbNET HW1 < 5.1.11 and mbNET/mbNET.rokey < 7.3.0 - Remote Code Execution via LUA Sandbox Escape
Title source: llmDescription
A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.
References (2)
Core 2
Core References
Various Sources
https://certvde.com/de/advisories/VDE-2025-065
Various Sources
https://certvde.com/de/advisories/VDE-2025-069
Scores
CVSS v3
7.2
EPSS
0.0064
EPSS Percentile
47.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-653
Status
published
Products (4)
Helmholz/REX 200/250
0.0.0 - 7.3.0
Helmholz/REX 300
0.0.0 - 5.1.11
MB connect line/mbNET HW1
0.0.0 - 5.1.11
MB connect line/mbNET/mbNET.rokey
0.0.0 - 7.3.0
Published
Jul 31, 2025
Tracked Since
Feb 18, 2026