Format String Injection Vulnerabilities in Abode Systems iota All-In-One Security Kit
CVE-2022-35876
What is CVE-2022-35876?
Four format string injection vulnerabilities have been identified in the XCMD testWifiAP functionality of the iota All-In-One Security Kit from Abode Systems, Inc. By utilizing specially-crafted configuration values, an attacker may exploit these vulnerabilities, potentially resulting in memory corruption, information disclosure, and denial of service conditions. The vulnerabilities are triggered through the manipulation of the default_key_id and key parameters within the testWifiAP XCMD handler, allowing attackers to execute harmful commands that could compromise system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iota All-In-One Security Kit 6.9X
iota All-In-One Security Kit 6.9Z
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved