eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Homematic_ccu2_firmware | Eq-3 | 2.35.16 (including) | 2.35.16 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.41.5 (including) | 2.41.5 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.41.8 (including) | 2.41.8 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.41.9 (including) | 2.41.9 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.45.6 (including) | 2.45.6 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.45.7 (including) | 2.45.7 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.47.10 (including) | 2.47.10 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.47.12 (including) | 2.47.12 (including) |
Homematic_ccu2_firmware | Eq-3 | 2.47.15 (including) | 2.47.15 (including) |