eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).
References
Link Resource
https://psytester.github.io/CVE-2020-12834/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-15T16:14:49

Updated: 2020-05-15T16:14:49

Reserved: 2020-05-13T00:00:00


Link: CVE-2020-12834

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-15T17:15:12.500

Modified: 2020-05-21T18:43:31.383


Link: CVE-2020-12834

JSON object: View

cve-icon Redhat Information

No data.

CWE