CVE-2024-22894: Alpha-Innotec Heat Pumps Firmware

Medium severity, CVSS 6.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

Affected products

  • Alpha-Innotec Heat Pumps Firmware: before 2.88.3 (fixed in 2.88.3); from 3.0.0, before 3.89.0 (fixed in 3.89.0); from 4.0.0, before 4.81.3 (fixed in 4.81.3)
  • Novelan Heat Pumps Firmware: before 2.88.3 (fixed in 2.88.3); from 3.0.0, before 3.89.0 (fixed in 3.89.0); from 4.0.0, before 4.81.3 (fixed in 4.81.3)

Published 2024-01-30. Last modified 2026-06-17.