vendor:
HomeMatic Zentrale CCU2
by:
Kacper Szurek
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution
78
CWE
Product Name: HomeMatic Zentrale CCU2
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2018
HomeMatic Zentrale CCU2 Unauthenticated RCE
The vulnerability allows unauthenticated attackers to execute arbitrary code on the target system. The issue is caused by improper handling of user input, which allows an attacker to inject malicious code and execute it in the context of the application.
Mitigation:
Apply the vendor-provided patch to fix the vulnerability. Additionally, restrict access to the affected system to trusted individuals only.