CVE-2024-24578

RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple issues within the Java based `HMIPServer.jar` component. RaspberryMatric includes a Java based `HMIPServer`, that can be accessed through URLs starting with `/pages/jpages`. The `FirmwareController` class does however not perform any session id checks, thus this feature can be accessed without a valid session. Due to this issue, attackers can gain remote code execution as root user, allowing a full system compromise. Version 3.75.6.20240316 contains a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:o:raspberrymatic:raspberrymatic:*:*:*:*:*:*:*:*

History

23 Dec 2025, 19:16

Type Values Removed Values Added
First Time Raspberrymatic raspberrymatic
Raspberrymatic
References () https://github.com/jens-maus/RaspberryMatic/security/advisories/GHSA-q967-q4j8-637h - () https://github.com/jens-maus/RaspberryMatic/security/advisories/GHSA-q967-q4j8-637h - Vendor Advisory, Exploit
CPE cpe:2.3:o:raspberrymatic:raspberrymatic:*:*:*:*:*:*:*:*

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://github.com/jens-maus/RaspberryMatic/security/advisories/GHSA-q967-q4j8-637h - () https://github.com/jens-maus/RaspberryMatic/security/advisories/GHSA-q967-q4j8-637h -

18 Mar 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 22:15

Updated : 2025-12-23 19:16


NVD link : CVE-2024-24578

Mitre link : CVE-2024-24578

CVE.ORG link : CVE-2024-24578


JSON object : View

Products Affected

raspberrymatic

  • raspberrymatic
CWE
CWE-23

Relative Path Traversal

CWE-306

Missing Authentication for Critical Function