PT-2021-14838 · Anker · Anker Eufy Homebase 2

Lilith >_>

·

Published

2021-10-12

·

Updated

2022-07-29

·

CVE-2021-21941

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anker Eufy Homebase 2 version 2.1.6.9h
Description A use-after-free issue exists in the pushMuxer CreatePushThread functionality. This can be exploited by a specially-crafted set of network packets, potentially leading to remote code execution.
Recommendations For Anker Eufy Homebase 2 version 2.1.6.9h, consider disabling the CreatePushThread functionality in the pushMuxer as a temporary workaround until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21941

Affected Products

Anker Eufy Homebase 2