CVE-2022-21806: Use After Free
Published Jun 17, 2022
·Updated
A use-after-free vulnerability exists in the mipscollector appsrvserver functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.
Affected Software
2 affected components
Anker Eufy Homebase 2 Firmware=2.1.8.5h
Anker Eufy Homebase 2
Event History
Jun 17, 2022
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-21806?
CVE-2022-21806 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2022-21806?
To fix CVE-2022-21806, update the Anker Eufy Homebase 2 firmware to the latest version provided by the vendor.
3
What devices are affected by CVE-2022-21806?
The Anker Eufy Homebase 2 version 2.1.8.5h is affected by CVE-2022-21806.
4
Can CVE-2022-21806 be exploited remotely?
Yes, CVE-2022-21806 can be exploited remotely through specially-crafted network packets.
5
What type of vulnerability is CVE-2022-21806?
CVE-2022-21806 is a use-after-free vulnerability affecting the mips_collector appsrv_server functionality.