Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3ww-xcqh-98r2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

EPSS

Процентиль: 98%
0.45806
Средний

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

EPSS

Процентиль: 98%
0.45806
Средний