Vulnerabilities > CVE-2018-7297 - Unspecified vulnerability in Eq-3 Homematic Central Control Unit Ccu2 Firmware
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Exploit-Db
description | Homematic CCU2 2.29.23 - Remote Command Execution. CVE-2018-7297. Webapps exploit for CGI platform |
file | exploits/cgi/webapps/44368.rb |
id | EDB-ID:44368 |
last seen | 2018-05-24 |
modified | 2018-03-30 |
platform | cgi |
port | |
published | 2018-03-30 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/44368/ |
title | Homematic CCU2 2.29.23 - Remote Command Execution |
type | webapps |
Packetstorm
data source | https://packetstormsecurity.com/files/download/146994/homematriccu222923-exec.txt |
id | PACKETSTORM:146994 |
last seen | 2018-04-03 |
published | 2018-03-31 |
reporter | Patrick Muench |
source | https://packetstormsecurity.com/files/146994/Homematic-CCU2-2.29.23-Remote-Command-Execution.html |
title | Homematic CCU2 2.29.23 Remote Command Execution |