CVE-2022-33195
10.0
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)
In your normal cycle
Critical by CVSS (10), but no sign of active exploitation.
Description
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_DefaultKeyID` in the function located at offset `0x1c7d28` of firmware 6.9Z, and even more specifically on the command execution occuring at offset `0x1c7fac`.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 3.4% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-10-25 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| goabode | iota all-in-one security kit firmware |
References
→ the Explorer · watch your stack · NVD