Home

Description

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

PUBLISHED Reserved 2026-02-24 | Published 2026-02-25 | Updated 2026-02-26 | Assigner ENISA

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
affected

1.0.4.205530
affected

Default status
unaffected

1.0.13.210200
affected

References

www.syss.de/...te/Publikationen/Advisories/SYSS-2025-009.txt third-party-advisory technical-description

cve.org (CVE-2026-27847)

nvd.nist.gov (CVE-2026-27847)

Download JSON