Vulnerability record · CVE-2021-33032 · published 22 July 2021
CVE-2021-33032: Unauthenticated OS command injection in eQ-3 HomeMatic CCU2/CCU3 WebUI
Eq 3 · Homematic Ccu2 Firmware
The WebUI component of eQ-3 HomeMatic CCU2 firmware up to 2.57.5 and CCU3 firmware up to 3.57.5 fails to neutralize input passed to system commands, allowing OS command injection. Because the flaw is reachable over the network without credentials, any host that can reach the WebUI can run commands as root on the controller.
Description
A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including version 3.57.5 allows remote unauthenticated attackers to execute system commands as root via a simple HTTP request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, root-level code execution, and a public exploit write-up make this an urgent fix.
What it is
The WebUI component of eQ-3 HomeMatic CCU2 firmware up to 2.57.5 and CCU3 firmware up to 3.57.5 fails to neutralize input passed to system commands, allowing OS command injection. Because the flaw is reachable over the network without credentials, any host that can reach the WebUI can run commands as root on the controller.
Impact
An attacker gains arbitrary command execution as root on the HomeMatic central control unit, giving full control of the device and any smart-home devices and data it manages.
Attack surface
Reachable over the network through the WebUI via a simple HTTP request, per the description. No authentication and no user interaction are required, matching the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
A public exploit write-up is referenced (Exploit tag), and EPSS is 0.52161 (99th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.
What to do
- Upgrade CCU2 to firmware 2.59.7 or later and CCU3 to firmware 3.59.6 or later, per the vendor changelogs.
- Do not expose the CCU WebUI to the internet; restrict access to a trusted management network or VPN.
- Segment HomeMatic controllers from general user and IoT networks so a compromised controller cannot pivot.
- Monitor vendor advisories for further firmware updates and apply them promptly.
Detection
- Review WebUI/HTTP access logs for requests containing shell metacharacters (;, |, $(), backticks) or unexpected command strings.
- Alert on outbound connections or process execution from the CCU that is not part of normal smart-home operation.
- Baseline and monitor firmware versions of CCU2/CCU3 devices to flag those below the fixed releases.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://novag.github.io/posts/homematic-unauthenticated-remote-code-execution/ | ExploitThird Party Advisory |
| https://www.eq-3.de/downloads/software/HM-CCU2-Firmware_Updates/HM-CCU-2.59.7/HM-CCU2-Changelog.2.59.7.pdf | Release NotesVendor Advisory |
| https://www.eq-3.de/downloads/software/firmware/ccu3-firmware/CCU3-Changelog.3.59.6.pdf | Release NotesVendor Advisory |
| https://novag.github.io/posts/homematic-unauthenticated-remote-code-execution/ | ExploitThird Party Advisory |
| https://www.eq-3.de/downloads/software/HM-CCU2-Firmware_Updates/HM-CCU-2.59.7/HM-CCU2-Changelog.2.59.7.pdf | Release NotesVendor Advisory |
| https://www.eq-3.de/downloads/software/firmware/ccu3-firmware/CCU3-Changelog.3.59.6.pdf | Release NotesVendor Advisory |
Track CVE-2021-33032 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33032), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.