← Vulnerability feed

Vulnerability record · CVE-2021-33032 · published 22 July 2021

CVE-2021-33032: Unauthenticated OS command injection in eQ-3 HomeMatic CCU2/CCU3 WebUI

Eq 3 · Homematic Ccu2 Firmware

The WebUI component of eQ-3 HomeMatic CCU2 firmware up to 2.57.5 and CCU3 firmware up to 3.57.5 fails to neutralize input passed to system commands, allowing OS command injection. Because the flaw is reachable over the network without credentials, any host that can reach the WebUI can run commands as root on the controller.

10.0 CVSS 3.1 Critical EPSS 52% · top 1.1% CWE-78 · OS command injection
10.0CVSS 3.1 base score, v2 10.0
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including version 3.57.5 allows remote unauthenticated attackers to execute system commands as root via a simple HTTP request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication, root-level code execution, and a public exploit write-up make this an urgent fix.

What it is

The WebUI component of eQ-3 HomeMatic CCU2 firmware up to 2.57.5 and CCU3 firmware up to 3.57.5 fails to neutralize input passed to system commands, allowing OS command injection. Because the flaw is reachable over the network without credentials, any host that can reach the WebUI can run commands as root on the controller.

Impact

An attacker gains arbitrary command execution as root on the HomeMatic central control unit, giving full control of the device and any smart-home devices and data it manages.

Attack surface

Reachable over the network through the WebUI via a simple HTTP request, per the description. No authentication and no user interaction are required, matching the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

A public exploit write-up is referenced (Exploit tag), and EPSS is 0.52161 (99th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Upgrade CCU2 to firmware 2.59.7 or later and CCU3 to firmware 3.59.6 or later, per the vendor changelogs.
  • Do not expose the CCU WebUI to the internet; restrict access to a trusted management network or VPN.
  • Segment HomeMatic controllers from general user and IoT networks so a compromised controller cannot pivot.
  • Monitor vendor advisories for further firmware updates and apply them promptly.

Detection

  • Review WebUI/HTTP access logs for requests containing shell metacharacters (;, |, $(), backticks) or unexpected command strings.
  • Alert on outbound connections or process execution from the CCU that is not part of normal smart-home operation.
  • Baseline and monitor firmware versions of CCU2/CCU3 devices to flag those below the fixed releases.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33032 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-12834Eq-3 homematic ccu2 firmware incorrect default permissions vulnerabilityeQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, …EPSS 11%9.8CVE-2019-18937Scriptparser project scriptparser missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attack…EPSS 34%9.8CVE-2019-18938Hm email project hm email missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers…EPSS 34%9.8CVE-2019-18939Hm-print project hm-print missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers …EPSS 41%9.8CVE-2019-16199Eq-3 homematic ccu2 firmware missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface …EPSS 8.7%9.8CVE-2019-9584Eq-3 homematic ccu2 firmware vulnerabilityeQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting…EPSS 2.7%9.8CVE-2019-9585Eq-3 homematic ccu2 firmware missing authentication for critical function vulnerabilityeQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res…EPSS 2.7%9.8CVE-2019-14985Eq-3 homematic ccu2 firmware improper authentication vulnerabilityeQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2021-33032), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.