Vulnerabilities > CVE-2018-7297 - Unspecified vulnerability in Eq-3 Homematic Central Control Unit Ccu2 Firmware 2.29.22

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
eq-3
critical
exploit available

Summary

Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

Vulnerable Configurations

Part Description Count
OS
Eq-3
1
Hardware
Eq-3
1

Exploit-Db

descriptionHomematic CCU2 2.29.23 - Remote Command Execution. CVE-2018-7297. Webapps exploit for CGI platform
fileexploits/cgi/webapps/44368.rb
idEDB-ID:44368
last seen2018-05-24
modified2018-03-30
platformcgi
port
published2018-03-30
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44368/
titleHomematic CCU2 2.29.23 - Remote Command Execution
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146994/homematriccu222923-exec.txt
idPACKETSTORM:146994
last seen2018-04-03
published2018-03-31
reporterPatrick Muench
sourcehttps://packetstormsecurity.com/files/146994/Homematic-CCU2-2.29.23-Remote-Command-Execution.html
titleHomematic CCU2 2.29.23 Remote Command Execution