AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-35885

HIGH · CVSS 8.8 EPSS 1.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-10-25 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It may lead to a denial-of-service condition.

CVE
CVE-2022-35885
Severity
HIGH
CVSS
8.8
EPSS
1.24%

Original NVD Description

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the `wpapsk_hex` HTTP parameter, as used within the `/action/wirelessConnect` handler.

Related CVEs

Other vulnerabilities affecting the same vendor(s)