eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://psytester.github.io/CVE-2019-18938/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:02:39.909Z
Reserved: 2019-11-13T00:00:00
Link: CVE-2019-18938
No data.
Status : Modified
Published: 2019-11-14T19:15:13.347
Modified: 2024-11-21T04:33:52.720
Link: CVE-2019-18938
No data.
OpenCVE Enrichment
No data.
Weaknesses