Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level account can create a new admin level account, read the service messages, clear the system protocol or modify/delete internal programs, etc. pp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eQ-3 HomeMatic CCU2和eQ-3 Homematic CCU3 授权问题漏洞
Vulnerability Description
eQ-3 Homematic CCU3和eQ-3 HomeMatic CCU2都是德国eQ-3公司的一款智能家居系统的中央控制单元。 eQ-3 Homematic CCU2和eQ-3 HomeMatic CCU2中存在授权问题漏洞,该漏洞源于程序使用会话ID进行身份验证,但缺少授权检查。攻击者可利用该漏洞读取服务消息,清除系统协议或修改/删除内部程序等。
CVSS Information
N/A
Vulnerability Type
N/A