VYPR
Unrated severityNVD Advisory· Published May 5, 2022· Updated Apr 15, 2025

CVE-2022-25989

CVE-2022-25989

Description

An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authentication bypass in Eufy Homebase 2's getpeermac() allows an attacker to spoof a trusted device via DHCP poisoning.

Vulnerability

The Eufy Homebase 2 (version 2.1.8.5h) contains an authentication bypass vulnerability in the libxm_av.so library's getpeermac() function. This function is used to authenticate smarthome devices connecting to the Homebase's hidden WiFi hotspot. By sending a specially-crafted DHCP packet, an attacker can bypass the MAC-based authentication check. The vulnerability is classified as CWE-290 (Authentication Bypass by Spoofing) [1].

Exploitation

An attacker must be within range of the Homebase 2's hidden WiFi network (typically used for smarthome device communication). No authentication is required to send DHCP packets on that network. The attacker performs DHCP poisoning by responding to DHCP requests with a crafted packet that spoofs the MAC address of a legitimate device. This causes the getpeermac() function to return the spoofed MAC, granting the attacker access as if they were a trusted device [1].

Impact

Successful exploitation allows the attacker to bypass authentication and impersonate a legitimate smarthome device. This can lead to unauthorized access to the Homebase 2's internal network, potentially allowing the attacker to interact with other connected devices, exfiltrate video data, or disrupt operations. The CVSSv3 score is 7.1 (High) with impacts to confidentiality, integrity, and availability [1].

Mitigation

As of the publication date (2022-05-05), the vendor had not released a patch. The confirmed vulnerable version is 2.1.8.5h. Users should monitor for firmware updates from Anker/Eufy. No workaround is documented. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.