First published: Tue Aug 13 2019(Updated: )
eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because the undocumented addons/xmlapi/exec.cgi script uses CMD_EXEC to execute TCL code from a POST request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
eQ-3 HomeMatic CCU2 firmware | <=1.2.0 | |
eQ-3 Homematic CCU2 | ||
eQ-3 HomeMatic CCU3 firmware | <=1.2.0 | |
eQ-3 HomeMatic CCU3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14984 is a vulnerability affecting eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed.
CVE-2019-14984 has a severity rating of 8.1 (high).
eQ-3 Homematic CCU2 firmware up to and including version 1.2.0, and eQ-3 Homematic CCU3 firmware up to and including version 1.2.0 are affected by CVE-2019-14984.
Unauthenticated attackers with access to the web interface can exploit CVE-2019-14984 by executing TCL code using the undocumented addons/xmlapi/exec.cgi script.
No, eQ-3 Homematic CCU2 and CCU3 devices themselves are not vulnerable to CVE-2019-14984, but only when certain addons and firmware versions are installed.