Vulnerability Description
A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded root password can lead to arbitrary command execution. An attacker can authenticate with hard-coded credentials to trigger this vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Goabode | Iota All-In-One Security Kit Firmware | 6.9z |
| Goabode | Iota All-In-One Security Kit | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1569ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1569ExploitThird Party Advisory
FAQ
What is CVE-2022-29889?
CVE-2022-29889 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded root password can lead to arbitrary command executi...
How severe is CVE-2022-29889?
CVE-2022-29889 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-29889?
Check the references section above for vendor advisories and patch information. Affected products include: Goabode Iota All-In-One Security Kit Firmware, Goabode Iota All-In-One Security Kit.