OS Command Injection Vulnerability in Abode Systems iota All-In-One Security Kit
CVE-2022-33195
10CRITICAL
Summary
Multiple OS command injection vulnerabilities have been identified in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit. These vulnerabilities allow an attacker to send specially crafted sequences of commands, which can lead to arbitrary command execution within the affected firmware versions 6.9X and 6.9Z. The exploitation of this vulnerability is rooted in the improper handling of the 'WL_DefaultKeyID', particularly during the command execution located at offset 0x1c7fac of the firmware.
Affected Version(s)
iota All-In-One Security Kit 6.9X
iota All-In-One Security Kit 6.9Z
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved