Back
CVE-2018-7297
CRITICAL
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Published: Feb 22, 2018
Modified: Jun 17, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| eq-3 | homematic_central_control_unit_ccu2_firmware | * |
GitHub Security Advisory GHSA-q64h-3pq3-w59f
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier...
References (4)
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
64.25%
Top 1% most likely to be exploited
Threat Score
58.5 / 100
Data Sources
NVD
EPSS
GitHub