CVE-2020-12834: Eq-3 CCU3 Firmware

Critical severity, CVSS 9.8. EPSS: 11.1% chance of exploitation in the next 30 days.

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

Affected products

  • Eq-3 CCU3 Firmware: up to and including 3.51.6
  • Eq-3 Homematic CCU2 Firmware: up to and including 2.51.6

Published 2020-05-15. Last modified 2026-06-17.