CVE-2026-40838 — An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings function due to improper neutralization of special elements in a SQL SELECT comman — CVE Database · The Intelligence Room