EUVD Vulnerability Catalog
EUVD-2026-89963
Severity: CRITICAL
Base Score: 9.8
CVSS Version: 3.1
Vulnerability Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.
This issue affects Trex MES: through 2026-09-29.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
Trex Digital Smart Manufacturing Systems Inc.
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
TR-CERT
EPSS Probability
0
Known Aliases
CVE-2026-18782
Published On
2026-09-30
Last Updated
2026-09-30