VYPR
Unrated severityNVD Advisory· Published Aug 13, 2019· Updated Aug 5, 2024

CVE-2019-14986

CVE-2019-14986

Description

eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Browser and Shell Command (as well as "Set root password") are exposed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unpatched CUxD AddOn (versions 2.2.0 and prior) for eQ-3 Homematic CCU2/CCU3 exposes administrative features to unauthenticated remote attackers without any access control.

Vulnerability

The eQ-3 Homematic CCU2 and CCU3 central units, when the third-party CUxD AddOn version 2.2.0 or earlier is installed, expose administrative interfaces such as File-Browser, Shell Command, and the ability to set the root password. These functions are accessible via the URL path /addons/cuxd/maintenance.html without any authentication. The vendor eQ-3 considers the AddOn a third-party extension and did not provide a central fix, leaving the remediation to the CUxD developer. [1]

Exploitation

An unauthenticated attacker with network access to the Homematic CCU2 or CCU3 web interface (typically port 80) can navigate directly to the maintenance page. From there, they can execute shell commands, browse the file system, or change the root password without requiring any prior access, credentials, or user interaction. [1]

Impact

Successful exploitation grants an attacker full administrative control over the Homematic CCU. They can read, modify, or delete all files on the device, execute arbitrary commands as root, and permanently lock out legitimate administrators by changing the root password. Given the network-accessible attack vector, this leads to complete compromise of the home automation central unit. [1]

Mitigation

The CUxD AddOn developer released version 2.3.0, which introduces proper access controls and fixes the vulnerability. Users must manually update the AddOn to version 2.3.0 or later via the Homematic WebUI AddOn management. No workarounds are documented; disabling the CUxD AddOn entirely also eliminates the vulnerable interface. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the report date. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.