First published: Thu Feb 22 2018(Updated: )
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
eQ-3 HomeMatic CCU2 firmware | <=2.29.22 | |
eQ-3 Homematic CCU2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7300 is a vulnerability in the User.setLanguage method in eQ-3 AG Homematic CCU2 firmware 2.29.2 and earlier that allows remote attackers to write arbitrary files to the device's filesystem and potentially execute remote code.
The severity of CVE-2018-7300 is critical with a score of 9.8.
CVE-2018-7300 affects eQ-3 AG Homematic CCU2 firmware 2.29.2 and earlier, allowing unauthenticated remote attackers to write arbitrary files on the device's filesystem.
CVE-2018-7300 can be exploited by unauthenticated attackers with access to the vulnerable system.
No, eQ-3 Homematic CCU2 is not vulnerable to CVE-2018-7300.
To fix CVE-2018-7300, upgrade the eQ-3 AG Homematic CCU2 firmware to version 2.29.22 or later.