High
CVE-2022-33194 CVSS:10
Abode could allow a remote attacker to execute arbitrary commands on the system, caused by an OS command injection in the XCMD setAlexa functionality. By sending a specially crafted XML payload, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2022-33193 CVSS:10
Abode could allow a remote attacker to execute arbitrary commands on the system, caused by an OS command injection in the XCMD setAlexa functionality. By sending a specially crafted XML payload, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Command Execution
Abode
Refer to Abode Systems, Inc. iota All-In-One Security Kit for patch, upgrade or suggested workaround information.