CVE-2022-25989: High severity eufy homebase 2 firmware vulnerability
Published May 5, 2022
·Updated
An authentication bypass vulnerability exists in the libxmav.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.
Affected Software
2 affected components
Anker Eufy Homebase 2 Firmware=2.1.8.5h
Anker Eufy Homebase 2
Event History
May 5, 2022
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-25989?
CVE-2022-25989 is an authentication bypass vulnerability in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h.
2
How does CVE-2022-25989 manifest?
CVE-2022-25989 can be triggered by a specially-crafted DHCP packet leading to authentication bypass.
3
What is the severity of CVE-2022-25989?
The severity of CVE-2022-25989 is rated as high with a score of 8.8.
4
How can an attacker exploit CVE-2022-25989?
An attacker can exploit CVE-2022-25989 by using DHCP poisoning to trigger the vulnerability.