CVE-2019-16199
9.8
CRITICAL · CVSS 3.1 · EPSS 8.7% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.74% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-09-17 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| eq-3 | homematic ccu2 |
| eq-3 | homematic ccu2 firmware |
| eq-3 | homematic ccu3 |
| eq-3 | homematic ccu3 firmware |
→ the Explorer · watch your stack · NVD