OS Command Injection Vulnerabilities in Abode Systems iota Security Kit
CVE-2022-33193
10CRITICAL
Summary
The iota All-In-One Security Kit from Abode Systems, Inc. is affected by multiple OS command injection vulnerabilities specifically in the XCMD testWifiAP functionality. These vulnerabilities allow attackers to execute arbitrary commands by sending carefully crafted sequences of commands that exploit the insecure handling of the WL_WPAPSK
configuration value in the firmware. The affected firmware versions include 6.9X and 6.9Z, where the vulnerabilities stem from unsafe function implementations that could potentially compromise device security.
Affected Version(s)
iota All-In-One Security Kit 6.9X
iota All-In-One Security Kit 6.9Z
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved