Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Helmholz

First CVE: Feb 16, 2021Active for: 5 yearsTotal CVEs: 17
19.2
VTI Score
Low

Helmholz manufactures a focused line of industrial networking and automation products, including the MyRex and Rex controller families that bridge industrial control systems and IT networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and cluster around authentication and access-control weaknesses—missing authentication on critical functions, improper privilege management, server-side request forgery, and exposure of sensitive configuration data—that are characteristic of legacy industrial devices retrofitted with connectivity. Defenders managing these controllers in operational environments should prioritize isolation and inventory, as these devices typically sit on the boundary between OT and IT; live severity and current exposure details are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Helmholz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2021
5 years ago
Most Recent CVE
Oct 15, 2024
647 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-45274CRITICAL
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
Oct 15, 20249.831NONO
CVE-2024-45275CRITICAL
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Oct 15, 20249.829NONO
CVE-2024-45273HIGH
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Oct 15, 20247.823NONO
CVE-2024-45271HIGH
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
Oct 15, 20247.823NONO
CVE-2020-35558HIGH
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, al
Feb 16, 20217.523NONO
CVE-2024-45276HIGH
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
Oct 15, 20247.522NONO
CVE-2024-45272HIGH
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
Oct 15, 20247.522NONO
CVE-2022-22520MEDIUM
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and m
Sep 14, 20225.321NONO
CVE-2020-35557MEDIUM
An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the accoun
Feb 16, 20216.521NONO
CVE-2020-35561MEDIUM
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allow
Feb 16, 20215.319NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
59%
29%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (11.8%)
Network15 (88.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (94.1%)
Unknown0 (0.0%)
Required1 (5.9%)
Privileges Required
Low8 (47.1%)
High0 (0.0%)
None9 (52.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Helmholz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Helmholz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Helmholz's Products

View all 2 CNAs →

Top CWEs