CVE-2021-21941CWE-368

A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h

Critical · published October 12, 2021

CVSS v3.0
10.0
EPSS
2%
Percentile
75.4
In the wild
Unconfirmed
What it is

🚨 A clever use-after-free vulnerability in Anker Eufy Homebase 2 could give attackers the keys to your smart home! 🔥 Think of it like a delivery driver who still accepts packages even after their job is done — the system trusts the packets without verifying if it should. These rogue packets can lead to unexpected chaos! An attacker could execute arbitrary code remotely, potentially turning your smart home into a playground for mischief—accessing cameras, tampering with settings, or even knocking on your door uninvited! That's absolutely devastating for your privacy and security.

Put simply

Think of it like a delivery driver who still accepts packages even after their job is done — the system trusts the packets without verifying if it should. These rogue packets can lead to unexpected chaos! This vulnerability arises from a use-after-free flaw in the CreatePushThread function, allowing specially-crafted network packets to manipulate memory and execute remote code without proper authorization.

What to do

An attacker could execute arbitrary code remotely, potentially turning your smart home into a playground for mischief—accessing cameras, tampering with settings, or even knocking on your door uninvited! That's absolutely devastating for your privacy and security. Immediate action is required: update your Eufy Homebase 2 to version 2.1.6.10 or later to patch this vulnerability. Additionally, consider enhancing your network security by monitoring incoming traffic and employing strong authentication methods. You've got this! Just follow these steps, and you'll be back in control of your smart home in no time! 🛡️

The record
Technical detail
CVSS v3.0
10.0 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.01679 · 75.4th percentile
Weakness
CWE-368 · Context Switching Race Condition
Published
2021-10-12T13:35Z
EPSS history
Timeline
  • 12 OCT 13:35Z
    A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h
    cvelistv5