{ "schema_version": "1.4.0", "id": "GHSA-gmh6-6p5f-p6qg", "modified": "2022-05-24T16:59:13Z", "published": "2022-05-24T16:59:13Z", "aliases": [ "CVE-2019-14423" ], "details": "A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14423" }, { "type": "WEB", "url": "https://noskill1337.github.io/homematic-with-cux-daemon-remote-code-execution" }, { "type": "WEB", "url": "https://www.eq-3.com/products/homematic.html" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-10-17T14:15:00Z" } }