VYPR
Unrated severityNVD Advisory· Published Oct 25, 2022· Updated Apr 15, 2025

CVE-2022-33195

CVE-2022-33195

Description

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the WL_DefaultKeyID in the function located at offset 0x1c7d28 of firmware 6.9Z, and even more specifically on the command execution occuring at offset 0x1c7fac.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OS command injection in Abode iota All-In-One Security Kit's WL_DefaultKeyID XCMD handler allows unauthenticated remote attackers to execute arbitrary commands.

Vulnerability

In the testWifiAP XCMD functionality of the Abode Systems, Inc. iota All-In-One Security Kit firmware versions 6.9X and 6.9Z, four OS command injection vulnerabilities exist. This specific instance resides in the unsafe use of the WL_DefaultKeyID parameter within the function located at offset 0x1c7d28 (with command execution at offset 0x1c7fac) of firmware 6.9Z. The vulnerability is classified as CWE-78 (OS Command Injection). [1]

Exploitation

An unauthenticated attacker can reach the vulnerable code path by sending a sequence of malicious XCMDs via a UDP service on port 55050, as described in TALOS-2022-1552. The attacker does not require any prior authentication or user interaction. By crafting a specially crafted WL_DefaultKeyID parameter within the testWifiAP XCMD, the attacker can inject arbitrary OS commands that are executed by the device. [1]

Impact

Successful exploitation allows the attacker to achieve arbitrary command execution on the iota device with full system privileges. This leads to complete compromise of confidentiality, integrity, and availability, as the attacker can read sensitive data, modify device configuration, or disrupt device operation. [1]

Mitigation

As of the publication date, no fixed version has been released by the vendor for this specific vulnerability. The vulnerable firmware versions (6.9X and 6.9Z) remain affected. Users should monitor vendor advisories for patches or consider isolating the device from untrusted networks. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.