CVE-2022-29472
Description
An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An OS command injection in the iota All-In-One Security Kit's web interface allows unauthenticated attackers to execute arbitrary commands.
Vulnerability
An OS command injection vulnerability exists in the util_set_serial_mac function of the Abode Systems iota All-In-One Security Kit firmware versions 6.9X and 6.9Z [1]. The function is reachable via the /action/factorySerialMacPost HTTP endpoint, which does not properly sanitize user-supplied input before using it in a system command. Specially-crafted HTTP requests can inject arbitrary OS commands [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP request to the /action/factorySerialMacPost endpoint without any authentication [1]. The Talos advisory notes that accessing this endpoint can be done without knowledge of username or password by leveraging other vulnerabilities (TALOS-2022-1554) [1]. The attacker needs only network access to the device's web interface; no user interaction is required [1].
Impact
Successful exploitation results in arbitrary command execution on the device with root privileges [1]. The full CVSS v3 score is 10.0, indicating the highest severity, with impacts on confidentiality, integrity, and availability, and the scope change to the entire system [1].
Mitigation
As of the publication date (2022-10-25), no fixed version has been released by the vendor [1]. Users should restrict network access to the web interface and monitor for vendor updates. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of that date.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
26.9X, 6.9Z+ 1 more
- (no CPE)range: 6.9X, 6.9Z
- (no CPE)range: 6.9X
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.