OS Command Injection Vulnerabilities in Abode Systems iota Security Kit
CVE-2022-33193

10CRITICAL

Key Information:

Vendor
Adobe
Vendor
CVE Published:
25 October 2022

Summary

The iota All-In-One Security Kit from Abode Systems, Inc. is affected by multiple OS command injection vulnerabilities specifically in the XCMD testWifiAP functionality. These vulnerabilities allow attackers to execute arbitrary commands by sending carefully crafted sequences of commands that exploit the insecure handling of the WL_WPAPSK configuration value in the firmware. The affected firmware versions include 6.9X and 6.9Z, where the vulnerabilities stem from unsafe function implementations that could potentially compromise device security.

Affected Version(s)

iota All-In-One Security Kit 6.9X

iota All-In-One Security Kit 6.9Z

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.