Description
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).
Published: 2020-05-15
Score: 9.8 Critical
EPSS: 45.8% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Eq-3 Ccu3 Firmware Homematic Ccu2 Homematic Ccu2 Firmware Homematic Ccu3
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T12:04:22.903Z

Reserved: 2020-05-13T00:00:00.000Z

Link: CVE-2020-12834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-15T17:15:12.500

Modified: 2024-11-21T05:00:22.087

Link: CVE-2020-12834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses