S4E just found a medium ssl lucky13 vulnerability scanner
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-9726 Scanner

CVE-2019-9726 scanner - Directory Traversal vulnerability in eQ-3 AG Homematic CCU3

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-9726
7.5
CVSS

Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

eQ-3 AG Homematic CCU3 is a home automation central control unit that allows users to remotely control various smart devices in their homes. The product is widely used by homeowners and smart home enthusiasts to monitor and manage everything from lights and temperature control to security systems and appliances. This central control unit is known for its reliability, flexibility, and ease of use.

The CVE-2019-9726 vulnerability detected in the eQ-3 AG Homematic CCU3 software is a directory traversal and arbitrary file read flaw that allows remote attackers to gain unauthorized access to the device's filesystem. This means that attackers can view and download any file on the system without proper authentication. This vulnerability can be exploited by anyone with access to the web interface, even if they are not authenticated.

When this vulnerability is exploited, it can lead to serious consequences, such as the exposure of sensitive information or the installation of malware. Attackers can use this vulnerability to access password files or other sensitive data, which can then be used to gain unauthorized access to other digital assets. Additionally, attackers can use this vulnerability to install malware or ransomware on the system, which can result in significant damage to the user's digital assets and devices.

In conclusion, the eQ-3 AG Homematic CCU3 vulnerability is a serious issue that can have significant consequences for users of the device. By taking the necessary precautions and staying informed about potential vulnerabilities, users can protect their digital assets and prevent unauthorized access. Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets and take the necessary steps to protect themselves.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of eQ-3 AG Homematic CCU3 should take the following precautions:

  • Update to the latest version of the software, which includes a patch for the vulnerability.
  • Enable two-factor authentication for the web interface to prevent unauthorized access.
  • Disable access to the web interface from external networks, only allowing access from trusted networks.
  • Monitor the device's filesystem for suspicious activity and unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-9726 scanner - Directory Traversal vulnerability in eQ-3 AG Homematic CCU3 S4E