CVE-2021-21952: Critical severity eufy homebase 2 firmware vulnerability
An authentication bypass vulnerability exists in the CMDDEVICEGETRSAKEYREQUEST functionality of the homesecurity binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21952?
CVE-2021-21952 is rated as critical due to the ability to bypass authentication and gain elevated privileges.
How do I fix CVE-2021-21952?
To fix CVE-2021-21952, update the Anker Eufy Homebase 2 firmware to the latest version that addresses this vulnerability.
What systems are affected by CVE-2021-21952?
CVE-2021-21952 affects the Anker Eufy Homebase 2 running firmware version 2.1.6.9h.
What type of vulnerability is CVE-2021-21952?
CVE-2021-21952 is an authentication bypass vulnerability that allows unauthorized access to the system.
What exploit does CVE-2021-21952 utilize?
CVE-2021-21952 can be exploited through a specially-crafted set of network packets targeting the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality.