PT-2019-13689 · Eq 3 · Homematic Ccu-Firmware
Joshua Lehr
·
Published
2019-10-17
·
Updated
2021-07-21
·
CVE-2019-14423
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
eQ-3 Homematic CCU-Firmware versions 2.35.16 through 2.45.6
Description
A Remote Code Execution issue in the addon CUx-Daemon allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.
Recommendations
For versions 2.35.16 through 2.45.6, consider disabling the CUx-Daemon addon until a patch is available to prevent remote code execution.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homematic Ccu-Firmware