CVE-2019-14423: Eq-3 CCU2 Firmware
High severity, CVSS 8.8. EPSS: 19.9% chance of exploitation in the next 30 days.
A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.
Affected products
- Eq-3 CCU2 Firmware: from 2.35.16, up to and including 2.45.6
- Eq-3 Cux-Daemon: from 1.11a, up to and including 2.2.0
Published 2019-10-17. Last modified 2026-06-17.