CVE-2018-7300
22.02.2018, 19:29
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
| Vendor | Product | Version |
|---|---|---|
| eq-3 | homematic_ccu2_firmware | 𝑥 ≤ 2.29.22 |
𝑥
= Vulnerable software versions