CVE-2019-14986
13.08.2019, 20:15
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Browser and Shell Command (as well as "Set root password") are exposed.Enginsight
Vendor | Product | Version |
---|---|---|
eq-3 | homematic_ccu2_firmware | 𝑥 < 2.3.0 |
eq-3 | homematic_ccu3_firmware | 𝑥 < 2.3.0 |
𝑥
= Vulnerable software versions