RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple issues within the Java based `HMIPServer.jar` component. RaspberryMatric includes a Java based `HMIPServer`, that can be accessed through URLs starting with `/pages/jpages`. The `FirmwareController` class does however not perform any session id checks, thus this feature can be accessed without a valid session. Due to this issue, attackers can gain remote code execution as root user, allowing a full system compromise. Version 3.75.6.20240316 contains a patch.

Project Subscriptions

Vendors Products
Raspberrymatic Subscribe
Raspberrymatic Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Raspberrymatic
Raspberrymatic raspberrymatic
CPEs cpe:2.3:o:raspberrymatic:raspberrymatic:*:*:*:*:*:*:*:*
Vendors & Products Raspberrymatic
Raspberrymatic raspberrymatic

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-26T13:54:04.130Z

Reserved: 2024-01-25T15:09:40.211Z

Link: CVE-2024-24578

cve-icon Vulnrichment

Updated: 2024-08-01T23:19:52.853Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-18T22:15:07.683

Modified: 2025-12-23T19:16:00.607

Link: CVE-2024-24578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses