CVE-2019-14423: Eq-3 CCU2 Firmware

High severity, CVSS 8.8. EPSS: 19.9% chance of exploitation in the next 30 days.

A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.

Affected products

  • Eq-3 CCU2 Firmware: from 2.35.16, up to and including 2.45.6
  • Eq-3 Cux-Daemon: from 1.11a, up to and including 2.2.0

Published 2019-10-17. Last modified 2026-06-17.