VYPR
Unrated severityNVD Advisory· Published Nov 14, 2019· Updated Aug 5, 2024

CVE-2019-18939

CVE-2019-18939

Description

eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated remote code execution in eQ-3 Homematic CCU2/CCU3 via HM-Print AddOn exec.cgi/exec1.cgi scripts executing TCL from HTTP POST.

Vulnerability

The HM-Print AddOn versions 1.2a and prior, installed on eQ-3 Homematic CCU2 firmware 2.47.20 and CCU3 firmware 3.47.18, contains improper access control (CWE-284) in the exec.cgi and exec1.cgi scripts. These scripts execute arbitrary TCL script content received via HTTP POST requests without any authentication, allowing unauthenticated remote code execution [1].

Exploitation

An unauthenticated attacker with network access to the web interface of the affected Homematic CCU can send a crafted HTTP POST request to either exec.cgi or exec1.cgi containing arbitrary TCL code. No prior authentication or user interaction is required. The TCL code is executed by the server with the privileges of the web server process [1].

Impact

Successful exploitation results in full remote code execution with the highest privileges, leading to complete compromise of confidentiality, integrity, and availability. The CVSSv3 base score is 10.0 (Critical) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H [1].

Mitigation

The HM-Print AddOn developer released version 2.3 on 03.11.2020, which fixes the vulnerability. Users should update to version 2.3 or later. The vendor eQ-3 stated they are not responsible for AddOns, so the fix must come from the AddOn developer. No workaround is available for unpatched versions [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.