← Vulnerability feed

Vulnerability record · CVE-2019-14984 · published 13 August 2019

CVE-2019-14984: Eq-3 homematic ccu2 firmware missing authentication for critical function vulnerability

Eq 3 · Homematic Ccu2 Firmware

eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because the undocumented addons/xmlapi/exec.cgi script uses CMD_EXEC to execute TCL code from a POST request.

8.1 CVSS 3.0 High EPSS 5.8% · top 7.2% CWE-306 · Missing authentication for critical function
8.1CVSS 3.0 base score, v2 6.8
5.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because the undocumented addons/xmlapi/exec.cgi script uses CMD_EXEC to execute TCL code from a POST request.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://psytester.github.io/CVE-2019-14984/ ExploitThird Party Advisory
https://psytester.github.io/CVE-2019-14984/ ExploitThird Party Advisory

Track CVE-2019-14984 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-33032Unauthenticated OS command injection in eQ-3 HomeMatic CCU2/CCU3 WebUIThe WebUI component of eQ-3 HomeMatic CCU2 firmware up to 2.57.5 and CCU3 firmware up to 3.57.5 fails to neutralize input passed to system commands, …EPSS 52%analysed9.8CVE-2020-12834Eq-3 homematic ccu2 firmware incorrect default permissions vulnerabilityeQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, …EPSS 11%9.8CVE-2019-18937Scriptparser project scriptparser missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attack…EPSS 34%9.8CVE-2019-18938Hm email project hm email missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers…EPSS 34%9.8CVE-2019-18939Hm-print project hm-print missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers …EPSS 41%9.8CVE-2019-16199Eq-3 homematic ccu2 firmware missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface …EPSS 8.7%9.8CVE-2019-9584Eq-3 homematic ccu2 firmware vulnerabilityeQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting…EPSS 2.7%9.8CVE-2019-9585Eq-3 homematic ccu2 firmware missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2019-14984), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.