VYPR
Unrated severityNVD Advisory· Published Oct 25, 2022· Updated Apr 15, 2025

CVE-2022-35881

CVE-2022-35881

Description

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via errorCode and errorDescription XML tags, as used within the DoUpdateUPnPbyService action handler.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Four format string injection vulnerabilities in Abode iota All-In-One Security Kit UPnP logging allow memory corruption, info disclosure, and DoS via malicious UPnP service.

Vulnerability

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit versions 6.9Z and 6.9X. The flaw resides in the DoUpdateUPnPbyService action handler, where the errorCode and errorDescription XML tags are used as format strings without sanitization. This allows an attacker to inject format specifiers into log messages, leading to memory corruption and information disclosure [1].

Exploitation

An attacker can host a malicious UPnP service on the same network (adjacent network position) and trigger the vulnerability by sending specially crafted UPnP negotiation messages. No authentication is required, and no user interaction is needed. The attacker crafts the errorCode or errorDescription fields with format string specifiers to exploit the logging function [1].

Impact

Successful exploitation can lead to memory corruption, arbitrary memory read (information disclosure), and denial of service. The attacker may gain the ability to read sensitive data from the device's memory or cause the device to crash. The CVSSv3 score is 7.1 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H) [1].

Mitigation

As of the publication date (2022-10-25), no official patch has been released by Abode Systems. Users are advised to monitor vendor updates and consider restricting UPnP services on the local network to reduce exposure. The affected versions are 6.9X and 6.9Z [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.