ZeroHour

CVE-2019-16199

PoC
CVSS 3.1
9.8 critical
EPSS
9%p95
Published
()
Modified
Description

eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.

Vendors
eq-3
Products
homematic ccu2 firmware, homematic ccu3 firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.