CVE-2024-51346
7.7Eufy · Homebase 2
A local security vulnerability in Eufy Homebase 2 version 3.3.4.1h allows unauthorized access to sensitive information due to a flawed cryptographic implementation.
Executive summary
Eufy Homebase 2 version 3.3.4.1h contains a critical cryptographic vulnerability that allows local attackers to access sensitive data, posing a significant risk to user privacy.
Vulnerability
The vulnerability stems from a weak cryptographic scheme that permits a local attacker to extract sensitive information without requiring authentication.
Business impact
The compromise of cryptographic secrets on a home security base station could lead to the unauthorized access of surveillance data, potentially exposing private video feeds or internal network credentials. With a CVSS score of 7.7, this flaw represents a high-severity risk that could result in severe reputational damage and the total loss of confidentiality for the affected premises.
Remediation
Immediate Action: Consult the official Eufy security portal for available firmware updates and apply them to the Homebase 2 unit as soon as they are released.
Proactive Monitoring: Inspect system access logs for any unauthorized physical interaction or unusual local connection attempts to the Homebase device.
Compensating Controls: Ensure the Homebase unit is kept in a physically secure, restricted area to prevent unauthorized local access, which is a required condition for this exploit.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the security research documentation provided by Victor Goeman.
Analyst recommendation
Given the exposure of sensitive cryptographic data, administrators must prioritize the security of their Homebase 2 units by restricting physical access. Users should monitor vendor communications for a definitive patch and apply it immediately to remediate the underlying cryptographic weakness.