VYPR
Unrated severityNVD Advisory· Published Oct 25, 2022· Updated Apr 15, 2025

CVE-2022-27804

CVE-2022-27804

Description

An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An OS command injection in the Abode iota All-In-One Security Kit's web interface allows authenticated remote attackers to execute arbitrary commands.

Vulnerability

An OS command injection vulnerability exists in the util_set_abode_code function of the Abode Systems, Inc. iota All-In-One Security Kit, specifically in the /action/factorySerialMacPost endpoint. The device, models 6.9X and 6.9Z, does not properly sanitize input when setting the ABODE_CODE bootargs variable, allowing an attacker to inject arbitrary operating system commands. The code path is reachable when the web interface is enabled, which can be achieved via separate vulnerabilities (TALOS-2022-1552 or TALOS-2022-1553). [1]

Exploitation

An attacker must first gain access to the web interface, which can be accomplished without authentication using TALOS-2022-1554. Subsequently, a specially crafted HTTP request to the /action/factorySerialMacPost endpoint is sent, containing malicious input that bypasses command sanitization. No special user interaction beyond sending the request is required; the attacker needs network access to the device. [1]

Impact

Successful exploitation leads to arbitrary command execution on the underlying operating system with root privileges. This results in full compromise of the device's confidentiality, integrity, and availability. An attacker can install malware, exfiltrate sensitive data, pivot to other network devices, or render the security kit inoperable. [1]

Mitigation

As of the publication date (2022-10-25), no official patch or firmware update has been released by Abode Systems for versions 6.9X and 6.9Z. Users are advised to restrict network access to the device's web interface and monitor for vendor updates. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.