PT-2019-13689 · Eq 3 · Homematic Ccu-Firmware

Joshua Lehr

·

Published

2019-10-17

·

Updated

2021-07-21

·

CVE-2019-14423

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions eQ-3 Homematic CCU-Firmware versions 2.35.16 through 2.45.6
Description A Remote Code Execution issue in the addon CUx-Daemon allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.
Recommendations For versions 2.35.16 through 2.45.6, consider disabling the CUx-Daemon addon until a patch is available to prevent remote code execution.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14423

Affected Products

Homematic Ccu-Firmware