Anker's Eufy Homebase 2 smart home hub devices have been found vulnerable to remote code execution (RCE) attacks, due to three flaws , one of which is particularly critical.
See also: Old Telerik flaws exploited for Cobalt Strike development

Homebase 2 is the video and networking gateway for all of Anker's Eufy smart home devices, including video doorbells, indoor security cameras, smart locks, alarm systems and more.
Homebase acts as a central hub for Eufy devices and connects to the cloud to provide services that enhance the functionality of these products, giving users remote control via an app.
However, researchers at Cisco Talos discovered that Homebase 2 has three potentially dangerous vulnerabilities, which could lead to privacy breaches, denial of service, and remote code execution.
But what are these dangerous defects?
The most critical of the three is CVE-2022-21806 with a CVSS severity rating of 10.0 , which is triggered by sending a specially crafted set of network packets to the target device.
The flaw lies in a user-after-free in the functionality of an internal server that Homebase uses to receive specially formatted messages from the network, such as for device pairing, configuration, and more.
See also: NSA and FBI: What flaws hackers use to target VPNs
The second vulnerability, tracked as CVE-2022-26073, is a high severity issue with a CVSS score of 7.4, also triggered remotely by sending a set of specially crafted network packets.

The exploit puts the device in a reboot state, so the primary impact is a denial of service. However, in the context of home security system impacts, there are many scenarios where this flaw would be useful to malicious actors.
Finally, there is CVE-2022-25989, a high severity authentication bypass issue with a CVSS score of 7.1, caused by a specially crafted DHCP packet, forcing Homebase to send traffic to an external server.
An attacker may be able to exploit this flaw to obtain the video stream from connected camera devices and spy on their owners.
Cisco Talos reported the above issues to Anker before the disclosure, giving it time to resolve the issues through security updates.
Anker addressed these security vulnerabilities by releasing firmware versions 3.1.8.7 and 3.1.8.7h, which were released in April 2022.
This means that most Homebase 2 devices out there that haven't updated their firmware after purchase are vulnerable to the above flaws.
See also: What flaws are hackers exploiting in blockchain and DeFi projects
Cisco provided technical details on how to exploit the above flaws so that threat actors can use the available information to launch real attacks.
The easiest way to update the firmware of a Eufy device is through the app, as explained on this support page.
