Known Vulnerabilities for Homematic Central Control Unit Ccu2 Firmware by Eq-3
Listed below are 5 of the newest known vulnerabilities associated with "Homematic Central Control Unit Ccu2 Firmware" by "Eq-3".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-7301 json | eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arb... | 9.8 - CRITICAL | 2018-02-22 | 2018-03-18 |
| CVE-2018-7299 json | Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticated att... | 8 - HIGH | 2018-02-22 | 2019-10-03 |
| CVE-2018-7298 json | In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloa... | 8.1 - HIGH | 2018-02-22 | 2019-10-03 |
| CVE-2018-7297 json | Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to o... | 9.8 - CRITICAL | 2018-02-22 | 2019-10-03 |
| CVE-2018-7296 json | Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remo... | 5.3 - MEDIUM | 2018-02-22 | 2019-10-03 |