VYPR
Unrated severityNVD Advisory· Published Oct 25, 2022· Updated Apr 15, 2025

CVE-2022-27805

CVE-2022-27805

Description

An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted network request can lead to arbitrary XCMD execution. An attacker can send a malicious XML payload to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authentication bypass in Abode iota All-In-One Security Kit allows remote attackers to execute arbitrary commands via specially-crafted XML payload.

Vulnerability

An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit versions 6.9X and 6.9Z. The device accepts commands received over an XMPP channel without proper authentication, assuming they are trustworthy from the secure connection. This allows an attacker to execute arbitrary XCMD commands by sending a specially-crafted network request containing a malicious XML payload [1].

Exploitation

An attacker can exploit this vulnerability by sending a malicious XML payload over the network to the iota device via the XMPP channel. No authentication or user interaction is required. The attack complexity is low, and the attacker needs network access to reach the device [1].

Impact

Successful exploitation leads to arbitrary command execution on the device with root privileges, resulting in full compromise of confidentiality, integrity, and availability (CIA). The attacker gains complete control over the iota All-In-One Security Kit [1].

Mitigation

As of the publication date (2022-10-25), no patched version has been released by Abode Systems, Inc. Users are advised to monitor for firmware updates. There are no known workarounds. The vulnerability is not listed on the CISA KEV catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.