VYPR
Unrated severityNVD Advisory· Published Oct 17, 2019· Updated Aug 5, 2024

CVE-2019-14424

CVE-2019-14424

Description

A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local File Inclusion in Homematic CCU firmware's CUx-Daemon addon allows authenticated attackers to read arbitrary files via the web interface.

Vulnerability

The vulnerability is a Local File Inclusion (LFI) in the CUx-Daemon addon version 1.11a (and up to 2.2.0 according to reference [2]) of the Homematic CCU-Firmware versions 2.35.16 to 2.45.6 [2]. The issue resides in the index.ccc script which does not sanitize the file parameter, allowing traversal [2].

Exploitation

An attacker must be authenticated to the Homematic CCU web interface [2]. They can send a crafted HTTP GET request to /addons/cuxd/index.ccc?file=/etc/shadow (or any other file) [2]. No special privileges beyond standard authentication are required.

Impact

Successful exploitation allows reading arbitrary files on the system, such as /etc/shadow, leading to disclosure of sensitive user information (e.g., password hashes) that could facilitate further attacks [2]. The confidentiality of the system is compromised.

Mitigation

The vendor eQ-3 has announced discontinuation of Homematic, but security updates are promised for at least ten years [1]. However, no specific patch for this vulnerability is mentioned in the references. Users should ensure they are on the latest firmware version (2.45.6 or later) and consider using the more secure Homematic IP system [1]. Alternatively, disable or remove the CUx-Daemon addon if not needed [2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.