eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-14T18:52:33

Updated: 2024-08-05T02:02:39.909Z

Reserved: 2019-11-13T00:00:00

Link: CVE-2019-18938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-11-14T19:15:13.347

Modified: 2021-07-21T11:39:23.747

Link: CVE-2019-18938

cve-icon Redhat

No data.