PT-2021-5580 · Anker · Anker Eufy Homebase 2

Lilith >_>

·

Published

2021-11-29

·

Updated

2023-06-26

·

CVE-2021-21951

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anker Eufy Homebase 2 version 2.1.6.9h
Description The issue is caused by an out-of-bounds write vulnerability in the read udp push config file function of the home security binary. This vulnerability can be exploited by a remote attacker using a specially-crafted network packet, potentially leading to code execution.
Recommendations For Anker Eufy Homebase 2 version 2.1.6.9h, consider disabling the read udp push config file function until a patch is available to prevent potential code execution. Restrict access to the home security binary to minimize the risk of exploitation. Avoid using the CMD DEVICE GET SERVER LIST REQUEST functionality in the affected binary until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-00010
CVE-2021-21951

Affected Products

Anker Eufy Homebase 2