OS Command Injection Vulnerability in Abode Systems iota All-In-One Security Kit
CVE-2022-33195
What is CVE-2022-33195?
Multiple OS command injection vulnerabilities have been identified in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit. These vulnerabilities allow an attacker to send specially crafted sequences of commands, which can lead to arbitrary command execution within the affected firmware versions 6.9X and 6.9Z. The exploitation of this vulnerability is rooted in the improper handling of the 'WL_DefaultKeyID', particularly during the command execution located at offset 0x1c7fac of the firmware.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iota All-In-One Security Kit 6.9X
iota All-In-One Security Kit 6.9Z
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved