VYPR
Unrated severityNVD Advisory· Published Oct 25, 2022· Updated Apr 15, 2025

CVE-2022-33194

CVE-2022-33194

Description

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the WL_Key and WL_DefaultKeyID configuration values in the function located at offset 0x1c7d28 of firmware 6.9Z , and even more specifically on the command execution occuring at offset 0x1c7f6c.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Abode iota All-In-One Security Kit 6.9X and 6.9Z contain OS command injection via the XCMD testWifiAP functionality, allowing unauthenticated remote code execution.

Vulnerability

Multiple OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit versions 6.9X and 6.9Z. The flaws are due to unsafe use of the WL_Key and WL_DefaultKeyID configuration values in the function at offset 0x1c7d28 of firmware 6.9Z, with command execution occurring at offset 0x1c7f6c. An attacker can send a sequence of malicious XCMD commands to exploit these vulnerabilities [1].

Exploitation

An unauthenticated attacker can send a specially crafted XCMD payload via the XMPP connection (or via UDP/55050 as noted in TALOS-2022-1552) to the iota device. The XCMD must contain a root ` element with a child specifying the target MAC address and a child with the attack parameters. By injecting OS commands into the WL_Key or WL_DefaultKeyID` configuration values, the attacker achieves arbitrary command execution [1].

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary commands on the iota gateway with root privileges. This leads to complete compromise of confidentiality, integrity, and availability (CIA) of the device, including potential access to connected sensors and cloud communication [1].

Mitigation

As of the publication date (2022-10-25), no fix has been released by the vendor. The vulnerable versions 6.9X and 6.9Z are confirmed affected. Users should monitor for firmware updates from Abode Systems and restrict network access to the iota device (especially UDP/55050) until a patch is available [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.