CVE-2020-12834
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.07% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- eq-3/homematic ccu2 firmware · eq-3/ccu3 firmware
- Source
- cve@mitre.org
References
- https://psytester.github.io/CVE-2020-12834/Exploit, Third Party Advisory
- https://psytester.github.io/CVE-2020-12834/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.