CVE-2019-16199

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
17/09/2019
Last modified:
24/08/2020

Description

eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:eq-3:homematic_ccu2_firmware:*:*:*:*:*:*:*:* 2.47.18 (excluding)
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:*:*:*:*:*:*:*:* 3.47.18 (excluding)
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools