VYPR
Vendor

eQ-3

Products
7
CVEs
7
Across products
8
Status
Private

Products

7

Recent CVEs

7
  • CVE-2019-18939Nov 14, 2019
    risk 0.02cvss epss 0.30

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST…

  • CVE-2019-18937Nov 14, 2019
    risk 0.02cvss epss 0.30

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request.

  • CVE-2019-14423Oct 17, 2019
    risk 0.00cvss epss 0.06

    A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.

  • CVE-2019-14424Oct 17, 2019
    risk 0.00cvss epss 0.00

    A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.

  • CVE-2019-13030Aug 14, 2019
    risk 0.00cvss epss 0.00

    eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to obtain mediola configuration details. This is related to improper access control for addons…

  • CVE-2019-9584Aug 14, 2019
    risk 0.00cvss epss 0.00

    eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/…

  • CVE-2019-14986Aug 13, 2019
    risk 0.00cvss epss 0.02

    eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Browser and Shell Command (as well as "Set root password") are exposed.