cve/2022/CVE-2022-35877.md
2024-06-18 02:51:15 +02:00

1.1 KiB

CVE-2022-35877

Description

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the default_key_id configuration parameter, as used within the testWifiAP XCMD handler

POC

Reference

Github

No PoCs found on GitHub currently.