eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute code and compromise the system.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.eq-3.com/products/homematic.html | vendor advisory |
https://noskill1337.github.io/homematic-ccu3-remote-code-execution | third party advisory exploit |