CVE-2022-35874 describes four critical format string injection vulnerabilities in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit firmware versions 6.9X and 6.9Z. An unauthenticated attacker can remotely trigger these flaws by manipulating specific configuration values (ssid and ssid_hex) and executing an XCMD. This can lead to severe consequences including memory corruption, information disclosure, and denial of service, as reflected by its CVSS score of 9.8 (Critical). Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.9xCPE matchmatch criteria | cpe:2.3:o:goabode:iota_all-in-one_security_kit_firmware:6.9x:*:*:*:*:*:*:* | ||
6.9zCPE matchmatch criteria | cpe:2.3:o:goabode:iota_all-in-one_security_kit_firmware:6.9z:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.