CVE-2019-14424: Eq-3 CCU2 Firmware
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
Affected products
- Eq-3 CCU2 Firmware: from 2.35.16, up to and including 2.45.6
- Eq-3 Cux-Daemon: from 1.11a, up to and including 2.2.0
Published 2019-10-17. Last modified 2026-06-17.