PT-2021-5412 · Anker · Anker Eufy Homebase 2

Lilith >_>

·

Published

2021-11-29

·

Updated

2023-06-26

·

CVE-2021-21950

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anker Eufy Homebase 2 version 2.1.6.9h
Description An out-of-bounds write issue exists in the CMD DEVICE GET SERVER LIST REQUEST functionality of the home security binary, specifically in the recv server device response msg process function. This can be exploited by a specially-crafted network packet, potentially leading to code execution.
Recommendations For Anker Eufy Homebase 2 version 2.1.6.9h, consider disabling the recv server device response msg process function until a patch is available to prevent potential code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2021-06254
CVE-2021-21950

Affected Products

Anker Eufy Homebase 2