Eq 3 manufactures home-automation control centers, particularly its HomeMatic CCU product line, which serve as central hubs for wireless smart-home networks and device management across residential deployments. The vendor's vulnerability disclosures span firmware and control-software components of these hubs, reflecting the complexity of embedded platforms that bridge local networks and remote management interfaces. While the vendor maintains a modest but durable presence in disclosed vulnerabilities, the exposure is concentrated in a narrow product family rather than a broad portfolio, and defenders should prioritize inventory of deployed CCU units and their firmware versions to track remediation applicability. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eq 3 over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7297CRITICAL Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on | Feb 22, 2018 | 9.8 | 77 | NO | YES |
CVE-2021-33032CRITICAL A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including vers | Jul 22, 2021 | 10.0 | 59 | NO | NO |
CVE-2018-7300CRITICAL Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbi | Feb 22, 2018 | 9.8 | 58 | NO | YES |
CVE-2019-18939CRITICAL eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interfac | Nov 14, 2019 | 9.8 | 50 | NO | NO |
CVE-2019-18937CRITICAL eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web inte | Nov 14, 2019 | 9.8 | 49 | NO | NO |
CVE-2019-18938CRITICAL eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interfa | Nov 14, 2019 | 9.8 | 45 | NO | NO |
CVE-2019-9726HIGH Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerabili | May 13, 2019 | 7.5 | 43 | NO | YES |
CVE-2020-12834CRITICAL eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers wi | May 15, 2020 | 9.8 | 36 | NO | NO |
CVE-2019-14985CRITICAL eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can acc | Aug 13, 2019 | 9.8 | 36 | NO | NO |
CVE-2019-14423HIGH A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system co | Oct 17, 2019 | 8.8 | 35 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eq 3.
Media articles that mention a CVE ID that affects a product developed by Eq 3 — matched by CVE ID, not by vendor name.