First published: Thu Feb 22 2018(Updated: )
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Homematic Central Control Unit Ccu2 Firmware | <=2.29.22 | |
Eq-3 Homematic Central Control Unit Ccu2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7296 is a vulnerability in the User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier that allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem.
The severity of CVE-2018-7296 is medium with a CVSS score of 5.3.
CVE-2018-7296 affects eQ-3 Homematic Central Control Unit CCU2 versions 2.29.2 and earlier.
CVE-2018-7296 can be exploited by unauthenticated attackers with access to the web interface.
No, Eq-3 Homematic Central Control Unit Ccu2 is not vulnerable to CVE-2018-7296.
To fix CVE-2018-7296, upgrade your eQ-3 Homematic Central Control Unit CCU2 to version 2.29.23 or newer.
You can find more information about CVE-2018-7296 at this link: http://atomic111.github.io/article/homematic-ccu2-fileread