CVE-2022-33193
Description
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the WL_WPAPSK configuration value in the function located at offset 0x1c7d28 of firmware 6.9Z.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated attacker can exploit OS command injection in the Abode iota All-In-One Security Kit to execute arbitrary commands.
Vulnerability
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of the Abode Systems, Inc. iota All-In-One Security Kit firmware versions 6.9X and 6.9Z. The vulnerability specifically focuses on the unsafe use of the WL_WPAPSK configuration value in the function located at offset 0x1c7d28 of firmware 6.9Z. The device receives XCMDs via an XMPP connection, and a service on UDP/55050 allows unauthenticated access to execute these XCMDs [1].
Exploitation
An attacker can send a sequence of malicious commands over the network to the iota device without authentication. The attack requires no user interaction and can be executed remotely. The attacker sends a crafted XCMD payload targeting the testWifiAP function, including a malicious WL_WPAPSK parameter that injects OS commands [1].
Impact
Successful exploitation leads to arbitrary OS command execution with root privileges. The attacker can fully compromise the device, achieving complete loss of confidentiality, integrity, and availability (CIA). The scope is changed as the attacker can impact resources beyond the vulnerable component, potentially using the device as a pivot point [1].
Mitigation
As of the publication date of the advisory (2022-10-25), no fixed version has been released by the vendor. The vulnerabilities affect firmware versions 6.9X and 6.9Z. Users should monitor vendor updates for a patch. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of this writing [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
26.9X, 6.9Z+ 1 more
- (no CPE)range: 6.9X, 6.9Z
- (no CPE)range: 6.9X
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.