CVE-2022-35886
Description
Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the default_key_id and key HTTP parameters, as used within the /action/wirelessConnect handler.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Format string injection in Abode iota security kit's wirelessConnect handler allows authenticated attackers to corrupt memory, leak data, or cause denial of service.
Vulnerability
Four format string injection vulnerabilities exist in the /action/wirelessConnect handler of the Abode Systems, Inc. iota All-In-One Security Kit versions 6.9Z and 6.9X. The vulnerabilities are triggered via the default_key_id and key HTTP parameters, which are passed to a logging function that uses vsnprintf with an attacker-controlled format string. This allows an authenticated attacker to inject format specifiers into the log output, leading to memory corruption, information disclosure, and denial of service [1].
Exploitation
An attacker must first authenticate to the device's web interface. No additional privileges or user interaction are required beyond authentication. The attacker sends a specially-crafted HTTP request to the /action/wirelessConnect endpoint, embedding format string tokens (e.g., %x, %n) in the default_key_id or key parameters. The device's logging function then processes these parameters as a format string, enabling the attacker to read from or write to arbitrary memory locations [1].
Impact
Successful exploitation can result in memory corruption, disclosure of sensitive stack data, and denial of service. The CVSSv3 score is 8.2 (High) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H, indicating low integrity impact but high availability impact. An attacker could potentially achieve arbitrary write primitives, escalating to full device compromise [1].
Mitigation
As of the publication date (2022-10-25), no official fix has been released by Abode Systems. Users should restrict network access to the iota device to trusted networks only and monitor vendor updates for a patched firmware version. The affected versions (6.9X and 6.9Z) remain vulnerable until a security update is provided [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
26.9Z, 6.9X+ 1 more
- (no CPE)range: 6.9Z, 6.9X
- (no CPE)range: 6.9X
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.