CVE-2022-33194 is a critical OS command injection vulnerability affecting Abode Systems, Inc. iota All-In-One Security Kit firmware versions 6.9X and 6.9Z. This flaw, stemming from unsafe handling of configuration values within the testWifiAP functionality, allows unauthenticated attackers to execute arbitrary commands remotely. With a CVSS score of 10.0, it presents a severe risk of complete compromise (confidentiality, integrity, and availability). Currently, there is no public exploit code, and it is not listed on the KEV catalog, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.9xCPE matchmatch criteria | cpe:2.3:o:goabode:iota_all-in-one_security_kit_firmware:6.9x:*:*:*:*:*:*:* | ||
6.9zCPE matchmatch criteria | cpe:2.3:o:goabode:iota_all-in-one_security_kit_firmware:6.9z:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.