CVE-2021-21954: OS Command Injection
Published Dec 9, 2021
·Updated
A command execution vulnerability exists in the wificountrycodeupdate functionality of the homesecurity binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.
Affected Software
2 affected components
Anker Eufy Homebase 2 Firmware=2.1.6.9h
Anker Eufy Homebase 2
Event History
Dec 9, 2021
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21954?
CVE-2021-21954 has a high severity rating due to the potential for arbitrary command execution.
2
How do I fix CVE-2021-21954?
To fix CVE-2021-21954, update the Anker Eufy Homebase 2 firmware to the latest version provided by Anker.
3
What versions are affected by CVE-2021-21954?
CVE-2021-21954 affects Anker Eufy Homebase 2 firmware version 2.1.6.9h.
4
What is the impact of CVE-2021-21954?
The impact of CVE-2021-21954 is that an attacker can execute commands on the vulnerable device remotely.
5
Is CVE-2021-21954 a local or remote vulnerability?
CVE-2021-21954 is a remote vulnerability that can be exploited through specially-crafted network packets.