Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-33207

Опубликовано: 25 окт. 2022
Источник: nvd
CVSS3: 10
CVSS3: 9.9
EPSS Низкий

Описание

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability focuses on a second unsafe use of the default_key_id HTTP parameter to construct an OS Command at offset 0x19B234 of the /root/hpgw binary included in firmware 6.9Z.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:goabode:iota_all-in-one_security_kit_firmware:6.9x:*:*:*:*:*:*:*
cpe:2.3:o:goabode:iota_all-in-one_security_kit_firmware:6.9z:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01109
Низкий

10 Critical

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.9
github
больше 3 лет назад

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability focuses on a second unsafe use of the `default_key_id` HTTP parameter to construct an OS Command at offset `0x19B234` of the `/root/hpgw` binary included in firmware 6.9Z.

EPSS

Процентиль: 78%
0.01109
Низкий

10 Critical

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-78