CVE-2022-33195
Description
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the WL_DefaultKeyID in the function located at offset 0x1c7d28 of firmware 6.9Z, and even more specifically on the command execution occuring at offset 0x1c7fac.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OS command injection in Abode iota All-In-One Security Kit's WL_DefaultKeyID XCMD handler allows unauthenticated remote attackers to execute arbitrary commands.
Vulnerability
In the testWifiAP XCMD functionality of the Abode Systems, Inc. iota All-In-One Security Kit firmware versions 6.9X and 6.9Z, four OS command injection vulnerabilities exist. This specific instance resides in the unsafe use of the WL_DefaultKeyID parameter within the function located at offset 0x1c7d28 (with command execution at offset 0x1c7fac) of firmware 6.9Z. The vulnerability is classified as CWE-78 (OS Command Injection). [1]
Exploitation
An unauthenticated attacker can reach the vulnerable code path by sending a sequence of malicious XCMDs via a UDP service on port 55050, as described in TALOS-2022-1552. The attacker does not require any prior authentication or user interaction. By crafting a specially crafted WL_DefaultKeyID parameter within the testWifiAP XCMD, the attacker can inject arbitrary OS commands that are executed by the device. [1]
Impact
Successful exploitation allows the attacker to achieve arbitrary command execution on the iota device with full system privileges. This leads to complete compromise of confidentiality, integrity, and availability, as the attacker can read sensitive data, modify device configuration, or disrupt device operation. [1]
Mitigation
As of the publication date, no fixed version has been released by the vendor for this specific vulnerability. The vulnerable firmware versions (6.9X and 6.9Z) remain affected. Users should monitor vendor advisories for patches or consider isolating the device from untrusted networks. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date. [1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
26.9X, 6.9Z+ 1 more
- (no CPE)range: 6.9X, 6.9Z
- (no CPE)range: 6.9X
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.