Homematic Central Control Unit Ccu2 Firmware
homematic_central_control_unit_ccu2_firmware
Vendor: Eq 3 • 5 CVEs
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Nov 21, 2024 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests to control the attached BidCos devices. |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Nov 21, 2024 Feb 22, 2018 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticated attackers to create or overwrite arbitrary files or install malicious software on the device. |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Nov 21, 2024 Feb 22, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protocol, which does not provide any cryptographic protection of the downloade...Show more |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Nov 21, 2024 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be ex...Show more |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Nov 21, 2024 Feb 22, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnera...Show more |