CVE-2019-18938

eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.
References
Link Resource
https://psytester.github.io/CVE-2019-18938/ Exploit Third Party Advisory
https://psytester.github.io/CVE-2019-18938/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8c:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8c:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8b:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8a:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7c:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7b:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 7 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7a:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 8 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 9 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.6:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 10 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.5:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 11 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.4:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 12 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.3:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 13 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.2:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 14 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.0:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 15 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20:*:*:*:*:*:*:*

Configuration 16 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8b:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 17 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8a:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 18 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.8:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 19 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7c:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 20 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7b:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 21 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7a:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 22 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.7:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 23 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.6:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 24 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.5:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 25 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.4:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 26 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.3:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 27 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.2:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

Configuration 28 (hide)

OR cpe:2.3:a:hm_email_project:hm_email:1.6.0:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18:*:*:*:*:*:*:*

History

21 Nov 2024, 04:33

Type Values Removed Values Added
References () https://psytester.github.io/CVE-2019-18938/ - Exploit, Third Party Advisory () https://psytester.github.io/CVE-2019-18938/ - Exploit, Third Party Advisory

Information

Published : 2019-11-14 19:15

Updated : 2024-11-21 04:33


NVD link : CVE-2019-18938

Mitre link : CVE-2019-18938

CVE.ORG link : CVE-2019-18938


JSON object : View

Products Affected

eq-3

  • homematic_ccu2_firmware
  • homematic_ccu2
  • homematic_ccu3
  • homematic_ccu3_firmware

hm_email_project

  • hm_email
CWE
CWE-306

Missing Authentication for Critical Function