An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.
The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1382 | third party advisory exploit |