CVE-2022-32775
Description
An integer overflow vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker can make an authenticated HTTP request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Integer overflow in Abode iota web interface /action/ipcamRecordPost leads to memory corruption. Requires authentication and web server enabled.
Vulnerability
An integer overflow vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Security Kit versions 6.9X and 6.9Z. The overflow occurs in the function at offset 0x1BC91C of the /root/hpgw binary. The web server must be enabled (disabled by default) for the endpoint to be reachable [1].
Exploitation
An attacker must be authenticated to the device's local web interface. The attacker sends a specially-crafted HTTP request to /action/ipcamRecordPost. No user interaction is required. The web server can be enabled via separate vulnerabilities (TALOS-2022-1552/1553) but is not intended for end-user access [1].
Impact
Successful exploitation leads to memory corruption, potentially allowing arbitrary code execution with high privileges. The vulnerability has a CVSSv3 score of 9.0 (Critical) with impacts to confidentiality, integrity, and availability [1].
Mitigation
No patch or fix has been disclosed by the vendor as of the publication date (2022-10-25). Until a fix is available, users should ensure the local web server remains disabled (default configuration) to reduce attack surface [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
26.9X and 6.9Z+ 1 more
- (no CPE)range: 6.9X and 6.9Z
- (no CPE)range: 6.9X
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.