Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2023-37822
Disclosure Date: October 03, 2024 (last updated October 30, 2024)
The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network. The WPA2-PSK generation of this dedicated network is flawed and solely based on the serial number. Due to the flawed generation process, the WPA2-PSK can be brute forced offline within seconds. This vulnerability allows an attacker in proximity to the dedicated wireless network to gain unauthorized access to the end user's primary network. The only requirement of the attack is proximity to the dedicated wireless network.
0
Attacker Value
Unknown
CVE-2022-29503
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-21806
Disclosure Date: June 15, 2022 (last updated February 23, 2025)
A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.
0
Attacker Value
Unknown
CVE-2022-25989
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-26073
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21953
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges.
0
Attacker Value
Unknown
CVE-2021-21952
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges.
0
Attacker Value
Unknown
CVE-2021-21955
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21954
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.
0
Attacker Value
Unknown
CVE-2021-21951
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution.
0