An OS command injection vulnerability exists in the...
Critical severity
Unreviewed
Published
Oct 25, 2022
to the GitHub Advisory Database
•
Updated Jun 28, 2023
Description
Published by the National Vulnerability Database
Oct 25, 2022
Published to the GitHub Advisory Database
Oct 25, 2022
Last updated
Jun 28, 2023
An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send an XML payload to trigger this vulnerability.
References