vendor:
Homematic CCU2
by:
Patrick Muench, Gregor Kopf
8.8
CVSS
HIGH
Arbitrary File Write
264
CWE
Product Name: Homematic CCU2
Affected Version From: 2.29.23
Affected Version To: 2.29.23
Patch Exists: YES
Related CWE: 2018-7300
CPE: a:eq-3:homematic_ccu2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Homematic CCU2 Arbitrary File Write
The Homematic CCU2 is vulnerable to an arbitrary file write vulnerability. This vulnerability allows an attacker to write arbitrary files to the file system of the Homematic CCU2. This vulnerability is due to the lack of authentication when sending requests to the Homematic CCU2 API. An attacker can exploit this vulnerability by sending a specially crafted request to the Homematic CCU2 API.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their Homematic CCU2 to the latest version.