9.8
CVSSv3

CVE-2018-7297

Published: 22/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and previous versions allows remote malicious users to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eq-3 homematic_central_control_unit_ccu2_firmware

Exploits

#!/usr/bin/ruby # Exploit Title: Homematic CCU2 Remote Command Execution # Date: 28-03-18 # Exploit Author: Patrick Muench, Gregor Kopf # Vendor Homepage: wwweq-3de # Software Link: wwweq-3de/service/downloadshtml?id=268 # Version: 22923 # CVE : 2018-7297 # Description: atomic111githubio/article/homematic-ccu2-remote ...