CRITICAL

CVE-2020-12834

CVSS v3

9.8

CRITICAL

EPSS Score

45.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

Technical details

Published
5/15/2020

Frequently asked questions

What is CVE-2020-12834?

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

Is CVE-2020-12834 actively exploited?

Active exploitation of CVE-2020-12834 has not been confirmed. The EPSS score is 45.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-12834?

CVE-2020-12834 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-12834 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.