eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 17, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Apr 4, 2024
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.
References