PT-2021-7056 · Anker · Anker Eufy Homebase

Lilith >_>

·

Published

2021-11-29

·

Updated

2022-07-29

·

CVE-2021-21953

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anker Eufy Homebase version 2.1.6.9h
Description The issue is related to the incorrect operation of the authentication process in the process msg() function. This can be exploited by a remote attacker to elevate their privileges in the target system through a man-in-the-middle attack.
Recommendations For Anker Eufy Homebase version 2.1.6.9h, consider restricting access to the process msg() function until a patch is available to prevent potential exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03114
CVE-2021-21953

Affected Products

Anker Eufy Homebase