First published: Tue Aug 13 2019(Updated: )
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Browser and Shell Command (as well as "Set root password") are exposed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
eQ-3 HomeMatic CCU2 firmware | <2.3.0 | |
eQ-3 Homematic CCU2 | ||
eQ-3 HomeMatic CCU3 firmware | <2.3.0 | |
eQ-3 HomeMatic CCU3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14986 is a vulnerability in eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed, allowing unauthenticated attackers to perform administrative operations through the web interface.
CVE-2019-14986 has a severity score of 8.1 (Critical).
The affected software versions are eQ-3 Homematic CCU2 firmware up to version 2.3.0 and eQ-3 Homematic CCU3 firmware up to version 2.3.0.
An attacker can exploit CVE-2019-14986 by accessing the web interface and using exposed features such as File-Browser, Shell Command, and "Set root password".
Yes, eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed are vulnerable to CVE-2019-14986.
To fix CVE-2019-14986, upgrade the CUxD AddOn to version 2.3.0 or later.