Anker records
13 published records for vendor anker.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-368 Context Switching Race Condition2
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-290 Authentication Bypass by Spoofing1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2021-21950No exploit | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufanker · eufy homebase 2 firmware · CWE-119 | Critical10.0 | — | 2.4% | Dec 8, 2021 |
41Plan | CVE-2021-21951No exploit | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufanker · eufy homebase 2 firmware · CWE-119 | Critical10.0 | — | 2.4% | Dec 8, 2021 |
40Plan | CVE-2021-21954No exploit | A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 anker · eufy homebase 2 firmware · CWE-78 | Critical9.9 | — | 2.4% | Dec 9, 2021 |
40Plan | CVE-2022-21806No exploit | A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h.anker · eufy homebase 2 firmware · CWE-368 | Critical9.8 | — | 2.3% | Jun 17, 2022 |
40Plan | CVE-2021-21940No exploit | A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h.anker · eufy homebase 2 firmware · CWE-122 | Critical10.0 | — | 1.3% | Oct 12, 2021 |
39Monitor | CVE-2022-29503No exploit | A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40.uclibc · uclibc · CWE-119 | Critical9.8 | — | 1.3% | Sep 29, 2022 |
39Monitor | CVE-2021-21952No exploit | An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy anker · eufy homebase 2 firmware · CWE-288 | Critical9.8 | — | 1.3% | Dec 22, 2021 |
37Monitor | CVE-2021-21941No exploit | A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h.anker · eufy homebase 2 firmware · CWE-368 | Critical9.0 | — | 1.7% | Oct 12, 2021 |
35Monitor | CVE-2022-25989No exploit | An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h.anker · eufy homebase 2 firmware · CWE-290 | High8.8 | — | 1.0% | May 5, 2022 |
32Monitor | CVE-2021-21953No exploit | An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.anker · eufy homebase 2 firmware · CWE-300 | High8.1 | — | 1.0% | Dec 22, 2021 |
30Monitor | CVE-2018-19980No exploit | Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operatianker · nebula capsule projector firmware · CWE-20 | High7.5 | — | 1.2% | Dec 8, 2018 |
30Monitor | CVE-2021-21955No exploit | An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebanker · eufy homebase 2 firmware · CWE-334 | High7.5 | — | 1.0% | Dec 9, 2021 |
26Monitor | CVE-2022-26073No exploit | A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h.anker · eufy homebase 2 firmware · CWE-190 | Medium6.5 | — | 0.7% | May 5, 2022 |
- CVE-2021-2195041Plan
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Euf
CriticalCVSS 10.0No exploitEPSS 2%anker · eufy homebase 2 firmwareDec 8, 2021
- CVE-2021-2195141Plan
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Euf
CriticalCVSS 10.0No exploitEPSS 2%anker · eufy homebase 2 firmwareDec 8, 2021
- CVE-2021-2195440Plan
A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2
CriticalCVSS 9.9No exploitEPSS 2%anker · eufy homebase 2 firmwareDec 9, 2021
- CVE-2022-2180640Plan
A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h.
CriticalCVSS 9.8No exploitEPSS 2%anker · eufy homebase 2 firmwareJun 17, 2022
- CVE-2021-2194040Plan
A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h.
CriticalCVSS 10.0No exploitEPSS 1%anker · eufy homebase 2 firmwareOct 12, 2021
- CVE-2022-2950339Monitor
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40.
CriticalCVSS 9.8No exploitEPSS 1%uclibc · uclibcSep 29, 2022
- CVE-2021-2195239Monitor
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy
CriticalCVSS 9.8No exploitEPSS 1%anker · eufy homebase 2 firmwareDec 22, 2021
- CVE-2021-2194137Monitor
A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h.
CriticalCVSS 9.0No exploitEPSS 2%anker · eufy homebase 2 firmwareOct 12, 2021
- CVE-2022-2598935Monitor
An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h.
HighCVSS 8.8No exploitEPSS 1%anker · eufy homebase 2 firmwareMay 5, 2022
- CVE-2021-2195332Monitor
An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.
HighCVSS 8.1No exploitEPSS 1%anker · eufy homebase 2 firmwareDec 22, 2021
- CVE-2018-1998030Monitor
Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operati
HighCVSS 7.5No exploitEPSS 1%anker · nebula capsule projector firmwareDec 8, 2018
- CVE-2021-2195530Monitor
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homeb
HighCVSS 7.5No exploitEPSS 1%anker · eufy homebase 2 firmwareDec 9, 2021
- CVE-2022-2607326Monitor
A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h.
MediumCVSS 6.5No exploitEPSS 1%anker · eufy homebase 2 firmwareMay 5, 2022