VYPR
Unrated severityNVD Advisory· Published Oct 25, 2022· Updated Apr 15, 2025

CVE-2022-29472

CVE-2022-29472

Description

An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An OS command injection in the iota All-In-One Security Kit's web interface allows unauthenticated attackers to execute arbitrary commands.

Vulnerability

An OS command injection vulnerability exists in the util_set_serial_mac function of the Abode Systems iota All-In-One Security Kit firmware versions 6.9X and 6.9Z [1]. The function is reachable via the /action/factorySerialMacPost HTTP endpoint, which does not properly sanitize user-supplied input before using it in a system command. Specially-crafted HTTP requests can inject arbitrary OS commands [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the /action/factorySerialMacPost endpoint without any authentication [1]. The Talos advisory notes that accessing this endpoint can be done without knowledge of username or password by leveraging other vulnerabilities (TALOS-2022-1554) [1]. The attacker needs only network access to the device's web interface; no user interaction is required [1].

Impact

Successful exploitation results in arbitrary command execution on the device with root privileges [1]. The full CVSS v3 score is 10.0, indicating the highest severity, with impacts on confidentiality, integrity, and availability, and the scope change to the entire system [1].

Mitigation

As of the publication date (2022-10-25), no fixed version has been released by the vendor [1]. Users should restrict network access to the web interface and monitor for vendor updates. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of that date.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.