CVE-2019-18939
Description
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated remote code execution in eQ-3 Homematic CCU2/CCU3 via HM-Print AddOn exec.cgi/exec1.cgi scripts executing TCL from HTTP POST.
Vulnerability
The HM-Print AddOn versions 1.2a and prior, installed on eQ-3 Homematic CCU2 firmware 2.47.20 and CCU3 firmware 3.47.18, contains improper access control (CWE-284) in the exec.cgi and exec1.cgi scripts. These scripts execute arbitrary TCL script content received via HTTP POST requests without any authentication, allowing unauthenticated remote code execution [1].
Exploitation
An unauthenticated attacker with network access to the web interface of the affected Homematic CCU can send a crafted HTTP POST request to either exec.cgi or exec1.cgi containing arbitrary TCL code. No prior authentication or user interaction is required. The TCL code is executed by the server with the privileges of the web server process [1].
Impact
Successful exploitation results in full remote code execution with the highest privileges, leading to complete compromise of confidentiality, integrity, and availability. The CVSSv3 base score is 10.0 (Critical) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H [1].
Mitigation
The HM-Print AddOn developer released version 2.3 on 03.11.2020, which fixes the vulnerability. Users should update to version 2.3 or later. The vendor eQ-3 stated they are not responsible for AddOns, so the fix must come from the AddOn developer. No workaround is available for unpatched versions [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- eQ-3/Homematic CCU2/CCU3description
- Range: <=1.2a
- Range: = 2.47.20
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- psytester.github.io/CVE-2019-18939/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.