Vulnerabilities > CVE-2018-7297 - Unspecified vulnerability in Eq-3 Homematic Central Control Unit Ccu2 Firmware 2.29.22
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Exploit-Db
description | Homematic CCU2 2.29.23 - Remote Command Execution. CVE-2018-7297. Webapps exploit for CGI platform |
file | exploits/cgi/webapps/44368.rb |
id | EDB-ID:44368 |
last seen | 2018-05-24 |
modified | 2018-03-30 |
platform | cgi |
port | |
published | 2018-03-30 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/44368/ |
title | Homematic CCU2 2.29.23 - Remote Command Execution |
type | webapps |
Packetstorm
data source | https://packetstormsecurity.com/files/download/146994/homematriccu222923-exec.txt |
id | PACKETSTORM:146994 |
last seen | 2018-04-03 |
published | 2018-03-31 |
reporter | Patrick Muench |
source | https://packetstormsecurity.com/files/146994/Homematic-CCU2-2.29.23-Remote-Command-Execution.html |
title | Homematic CCU2 2.29.23 Remote Command Execution |