First published: Tue Oct 25 2022(Updated: )
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the `WL_WPAPSK` configuration value in the function located at offset `0x1c7d28` of firmware 6.9Z.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Goabode Iota All-in-one Security Kit Firmware | =6.9x | |
Goabode Iota All-in-one Security Kit Firmware | =6.9z |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-33193.
The severity level of CVE-2022-33193 is critical (10 out of 10).
These vulnerabilities occur due to four OS command injection vulnerabilities in the XCMD testWifiAP functionality.
An attacker can send malicious commands to trigger the vulnerabilities, leading to arbitrary command execution.
Currently, no fix information is available. It is recommended to follow the vendor's advisory for updates and patches.