First published: Mon May 13 2019(Updated: )
Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Ccu3 Firmware | <=3.43.15 | |
Eq-3 Ccu3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9726 is a directory traversal vulnerability in eQ-3 AG Homematic CCU3 3.43.15 and earlier, which allows remote attackers to read arbitrary files on the device's filesystem.
CVE-2019-9726 has a severity score of 7.5 (High).
An attacker with access to the web interface can exploit CVE-2019-9726 to read arbitrary files on the device's filesystem.
eQ-3 AG Homematic CCU3 versions up to and including 3.43.15 are affected by CVE-2019-9726.
No, the Eq-3 Ccu3 software is not vulnerable to CVE-2019-9726.
Upgrade to a version of eQ-3 AG Homematic CCU3 that is later than 3.43.15 to fix CVE-2019-9726.