Security Advisory

CVE-2018-7297

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-02-22 19:00:00
Last updated 2024-08-05 06:24:11
Assigner mitre
State PUBLISHED

Description

Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.