PT-2021-5580 · Anker · Anker Eufy Homebase 2
Lilith >_>
·
Published
2021-11-29
·
Updated
2023-06-26
·
CVE-2021-21951
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Anker Eufy Homebase 2 version 2.1.6.9h
Description
The issue is caused by an out-of-bounds write vulnerability in the
read udp push config file function of the home security binary. This vulnerability can be exploited by a remote attacker using a specially-crafted network packet, potentially leading to code execution.Recommendations
For Anker Eufy Homebase 2 version 2.1.6.9h, consider disabling the
read udp push config file function until a patch is available to prevent potential code execution. Restrict access to the home security binary to minimize the risk of exploitation. Avoid using the CMD DEVICE GET SERVER LIST REQUEST functionality in the affected binary until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anker Eufy Homebase 2