CVE-2024-22894

MEDIUM

Alpha Innotec and Novelan Heat Pumps Firmware < 2.88.3 - Inadequate Encryption Strength in Password Component

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-22894. PoCs published by Jaarden.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-22894, a vulnerability in Alpha Innotec and Novelan heatpumps where a hardcoded 3DES-encrypted root password ('eschi') is exposed in the firmware. The writeup includes steps to exploit the vulnerability via SSH, affected versions, and a timeline of responsible disclosure.

Description

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

Exploits (1)

nomisec WRITEUP 3 stars
by Jaarden · poc
https://github.com/Jaarden/CVE-2024-22894

This repository provides a detailed technical analysis of CVE-2024-22894, a vulnerability in Alpha Innotec and Novelan heatpumps where a hardcoded 3DES-encrypted root password ('eschi') is exposed in the firmware. The writeup includes steps to exploit the vulnerability via SSH, affected versions, and a timeline of responsible disclosure.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Alpha Innotec and Novelan heatpumps (Luxtronic controller) with firmware versions prior to V2.88.3, V3.89.0, or V4.81.3
No auth needed
Prerequisites: Network access to the heatpump via LAN (RJ-45) · SSH client supporting diffie-hellman-group1-sha1 and aes256-cbc
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 6.8
EPSS 0.0073
EPSS Percentile 49.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-326
Status published
Products (2)
alpha-innotec/heat_pumps_firmware < 2.88.3
novelan/heat_pumps_firmware < 2.88.3
Published Jan 30, 2024
Tracked Since Feb 18, 2026