Anker Eufy Homebase 2 Firmware vulnerabilities

12 known vulnerabilities affecting anker/eufy_homebase_2_firmware.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2022-29503CRITICALCVSS 9.8v2.1.8.8h2022-09-29
CVE-2022-29503 [CRITICAL] CWE-119 CVE-2022-29503: A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9. A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.
nvd
CVE-2022-21806CRITICALCVSS 9.8v2.1.8.5h2022-06-17
CVE-2022-21806 [CRITICAL] CWE-368 CVE-2022-21806: A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Euf A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.
nvd
CVE-2022-25989HIGHCVSS 8.8v2.1.8.5h2022-05-05
CVE-2022-25989 [HIGH] CWE-290 CVE-2022-25989: An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.
nvd
CVE-2022-26073MEDIUMCVSS 6.5v2.1.8.5h2022-05-05
CVE-2022-26073 [MEDIUM] CWE-190 CVE-2022-26073: A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.
nvd
CVE-2021-21952CRITICALCVSS 9.8v2.1.6.9h2021-12-22
CVE-2021-21952 [CRITICAL] CWE-288 CVE-2021-21952: An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges.
nvd
CVE-2021-21953HIGHCVSS 8.1v2.1.6.9h2021-12-22
CVE-2021-21953 [HIGH] CWE-300 CVE-2021-21953: An authentication bypass vulnerability exists in the process_msg() function of the home_security bin An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges.
nvd
CVE-2021-21954CRITICALCVSS 9.9v2.1.6.9h2021-12-09
CVE-2021-21954 [CRITICAL] CWE-78 CVE-2021-21954: A command execution vulnerability exists in the wifi_country_code_update functionality of the home_s A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.
nvd
CVE-2021-21955HIGHCVSS 7.5v2.1.6.9h2021-12-09
CVE-2021-21955 [HIGH] CWE-334 CVE-2021-21955: An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.
nvd
CVE-2021-21951CRITICALCVSS 10.0v2.1.6.9h2021-12-08
CVE-2021-21951 [CRITICAL] CWE-119 CVE-2021-21951: An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution.
nvd
CVE-2021-21950CRITICALCVSS 10.0v2.1.6.9h2021-12-08
CVE-2021-21950 [CRITICAL] CWE-119 CVE-2021-21950: An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted network packet can lead to code execution.
nvd
CVE-2021-21940CRITICALCVSS 10.0v2.1.6.9h2021-10-12
CVE-2021-21940 [CRITICAL] CWE-122 CVE-2021-21940: A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2021-21941CRITICALCVSS 9.0v2.1.6.9h2021-10-12
CVE-2021-21941 [CRITICAL] CWE-368 CVE-2021-21941: A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to remote code execution.
nvd