CVE-2019-14985: Eq-3 Homematic CCU2 Firmware
Critical severity, CVSS 9.8. EPSS: 7.5% chance of exploitation in the next 30 days.
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.
Affected products
- Eq-3 Homematic CCU2 Firmware: version 2.35.16 only; version 2.41.5 only; version 2.41.8 only; version 2.41.9 only; version 2.45.6 only; version 2.45.7 only; …
- Eq-3 Homematic CCU3 Firmware: version 3.41.11 only; version 3.43.16 only; version 3.45.5 only; version 3.45.7 only; version 3.47.10 only; version 3.47.15 only
Published 2019-08-13. Last modified 2026-06-17.