CVE-2022-21806CWE-368

A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h

Critical · published June 17, 2022

CVSS v3.0
10.0
EPSS
2%
Percentile
82.5
In the wild
Unconfirmed
What it is

🚨 A crafty set of network packets is all it takes to seize control of your Anker Eufy Homebase 2! 🔥 Think of this vulnerability like a sneaky delivery driver who can drop off a package that doesn't belong at your door — once it’s there, they can waltz right in and make themselves at home! An attacker could remotely execute code on your device, which means they could potentially access and control your home network. This could lead to catastrophic consequences, like invading your privacy or creating an entry point for further attacks on other devices. Yikes!

Put simply

Think of this vulnerability like a sneaky delivery driver who can drop off a package that doesn't belong at your door — once it’s there, they can waltz right in and make themselves at home! This CVE arises from a use-after-free flaw in the mips_collector of the Anker Eufy Homebase 2, allowing attackers to send specially-crafted packets that lead to remote code execution without proper authorization.

What to do

An attacker could remotely execute code on your device, which means they could potentially access and control your home network. This could lead to catastrophic consequences, like invading your privacy or creating an entry point for further attacks on other devices. Yikes! To protect your device, update to version 2.1.8.6 or later immediately. Additionally, consider reviewing your network security settings to limit exposure to potential threats. Don't wait — this is critical! You've got this! Follow these steps to secure your device, and you'll be a security hero in no time! 🛡️

The record
Technical detail
CVSS v3.0
10.0 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.02342 · 82.5th percentile
Weakness
CWE-368 · Context Switching Race Condition
Published
2022-06-17T17:40Z
EPSS history
Timeline
  • 17 JUN 17:40Z
    A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h
    cvelistv5