Vulnerability Description
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eq-3 | Homematic Ccu2 Firmware | 2.35.16 |
| Eq-3 | Homematic Ccu2 | - |
| Eq-3 | Homematic Ccu3 Firmware | 3.41.11 |
| Eq-3 | Homematic Ccu3 | - |
Related Weaknesses (CWE)
References
- https://psytester.github.io/CVE-2019-14985/ExploitThird Party Advisory
- https://psytester.github.io/CVE-2019-14985/ExploitThird Party Advisory
FAQ
What is CVE-2019-14985?
CVE-2019-14985 is a vulnerability with a CVSS score of 9.8 (CRITICAL). eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC vir...
How severe is CVE-2019-14985?
CVE-2019-14985 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-14985?
Check the references section above for vendor advisories and patch information. Affected products include: Eq-3 Homematic Ccu2 Firmware, Eq-3 Homematic Ccu2, Eq-3 Homematic Ccu3 Firmware, Eq-3 Homematic Ccu3.