CVE-2019-14424
Description
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Local File Inclusion in Homematic CCU firmware's CUx-Daemon addon allows authenticated attackers to read arbitrary files via the web interface.
Vulnerability
The vulnerability is a Local File Inclusion (LFI) in the CUx-Daemon addon version 1.11a (and up to 2.2.0 according to reference [2]) of the Homematic CCU-Firmware versions 2.35.16 to 2.45.6 [2]. The issue resides in the index.ccc script which does not sanitize the file parameter, allowing traversal [2].
Exploitation
An attacker must be authenticated to the Homematic CCU web interface [2]. They can send a crafted HTTP GET request to /addons/cuxd/index.ccc?file=/etc/shadow (or any other file) [2]. No special privileges beyond standard authentication are required.
Impact
Successful exploitation allows reading arbitrary files on the system, such as /etc/shadow, leading to disclosure of sensitive user information (e.g., password hashes) that could facilitate further attacks [2]. The confidentiality of the system is compromised.
Mitigation
The vendor eQ-3 has announced discontinuation of Homematic, but security updates are promised for at least ten years [1]. However, no specific patch for this vulnerability is mentioned in the references. Users should ensure they are on the latest firmware version (2.45.6 or later) and consider using the more secure Homematic IP system [1]. Alternatively, disable or remove the CUx-Daemon addon if not needed [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- eQ-3/Homematic CCU-Firmwaredescription
- Range: 2.35.16 - 2.45.6
- Range: 1.11a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- noskill1337.github.io/homematic-with-cux-daemon-local-file-inclusionmitrex_refsource_MISC
- www.eq-3.com/products/homematic.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.