CVE-2022-33189
Description
An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OS command injection in Abode iota All-In-One Security Kit 6.9Z via specially-crafted XCMD allows unauthenticated remote code execution.
Vulnerability
The iota All-In-One Security Kit (version 6.9Z) contains an OS command injection vulnerability in the setAlexa XCMD handler. The device receives XCMDs (XML payloads) via an XMPP connection or through a UDP service on port 55050 that allows unauthenticated access [1]. A specially-crafted XML payload can inject arbitrary OS commands.
Exploitation
An unauthenticated attacker can send a malicious XML payload to the iota device via the UDP service on port 55050 (or potentially via XMPP). The payload targets the setAlexa XCMD and includes injected commands. No authentication or user interaction is required; the attacker only needs network access to the device.
Impact
Successful exploitation allows arbitrary command execution with root privileges, leading to full compromise of the device. The attacker can read sensitive data, modify system configuration, or use the device as a pivot point in the network. The CVSS score is 10.0 (Critical) with impact on confidentiality, integrity, and availability.
Mitigation
As of the advisory publication (October 2022), no patch was available. The vendor (Abode Systems) was notified but no fix had been released. Users should monitor for firmware updates and restrict network access to the iota device, especially blocking UDP port 55050 from untrusted networks. The device is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2=6.9Z+ 1 more
- (no CPE)range: =6.9Z
- (no CPE)range: 6.9Z
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.