Vulnerabilities > EQ 3 > Ccu3 Firmware > 3.43.16
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-05-15 | CVE-2020-12834 | Incorrect Default Permissions vulnerability in Eq-3 Ccu3 Firmware and Homematic Ccu2 Firmware eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset). | 9.8 |
2019-08-07 | CVE-2019-14474 | Improper Input Validation vulnerability in Eq-3 Ccu3 Firmware eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. | 7.5 |
2019-08-06 | CVE-2019-14473 | Missing Authorization vulnerability in Eq-3 Ccu2 Firmware and Ccu3 Firmware eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. | 8.8 |
2019-08-05 | CVE-2019-14475 | Missing Authorization vulnerability in Eq-3 Ccu2 Firmware and Ccu3 Firmware eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. | 7.5 |