CVE-2021-21955: High severity eufy homebase 2 firmware vulnerability
An authentication bypass vulnerability exists in the getaeskeyinfobypacketid() function of the homesecurity binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21955?
CVE-2021-21955 is an authentication bypass vulnerability in the get_aes_key_info_by_packetid() function of Anker Eufy Homebase 2 2.1.6.9h.
How does CVE-2021-21955 work?
CVE-2021-21955 allows an attacker to bypass authentication by sniffing network traffic to recover passwords.
What is the severity of CVE-2021-21955?
The severity of CVE-2021-21955 is high.
How can I fix CVE-2021-21955?
To fix CVE-2021-21955, it is recommended to update Anker Eufy Homebase 2 firmware to version 2.1.6.9h or later.
Where can I find more information about CVE-2021-21955?
You can find more information about CVE-2021-21955 in the vulnerability report by Talos Intelligence: https://talosintelligence.com/vulnerability_reports/TALOS-2021-1382.