VYPR
Medium severity6.5NVD Advisory· Published Oct 17, 2019· Updated Jun 17, 2026

CVE-2019-14424

CVE-2019-14424

Description

A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • eQ-3/CUx-Daemon2 versions
    cpe:2.3:a:eq-3:cux-daemon:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:eq-3:cux-daemon:*:*:*:*:*:*:*:*range: >=1.11a,<=2.2.0
    • (no CPE)range: 1.11a
  • cpe:2.3:o:eq-3:ccu2_firmware:*:*:*:*:*:*:*:*
    Range: >=2.35.16,<=2.45.6
  • eQ-3/Homematic CCU-Firmwaredescription
  • Range: 2.35.16 - 2.45.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.