← Vulnerability feed

Vulnerability record · CVE-2019-15850 · published 17 October 2019

CVE-2019-15850: Eq-3 homematic ccu3 firmware missing authorization vulnerability

Eq 3 · Homematic Ccu3 Firmware

eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute code and compromise the system.

8.8 CVSS 3.1 High EPSS 16% · top 3.3% CWE-862 · Missing authorization
8.8CVSS 3.1 base score, v2 9.0
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute code and compromise the system.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15850 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-33032Unauthenticated OS command injection in eQ-3 HomeMatic CCU2/CCU3 WebUIThe WebUI component of eQ-3 HomeMatic CCU2 firmware up to 2.57.5 and CCU3 firmware up to 3.57.5 fails to neutralize input passed to system commands, …EPSS 52%analysed9.8CVE-2019-18937Scriptparser project scriptparser missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attack…EPSS 34%9.8CVE-2019-18938Hm email project hm email missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers…EPSS 34%9.8CVE-2019-18939Hm-print project hm-print missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers …EPSS 41%9.8CVE-2019-16199Eq-3 homematic ccu2 firmware missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface …EPSS 8.7%9.8CVE-2019-9584Eq-3 homematic ccu2 firmware vulnerabilityeQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting…EPSS 2.7%9.8CVE-2019-9585Eq-3 homematic ccu2 firmware missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res…EPSS 2.7%9.8CVE-2019-14985Eq-3 homematic ccu2 firmware improper authentication vulnerabilityeQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2019-15850), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.