goabode records
40 published records for vendor goabode.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')16
- CWE-134 Use of Externally-Controlled Format String14
- CWE-489 Active Debug Code2
- CWE-798 Use of Hard-coded Credentials2
- CWE-121 Stack-based Buffer Overflow1
- CWE-415 Double Free1
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2022-33195No exploit | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical10.0 | — | 3.3% | Oct 25, 2022 |
41Plan | CVE-2022-33192No exploit | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical10.0 | — | 3.3% | Oct 25, 2022 |
41Plan | CVE-2022-33193No exploit | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical10.0 | — | 3.2% | Oct 25, 2022 |
41Plan | CVE-2022-33194No exploit | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical10.0 | — | 3.2% | Oct 25, 2022 |
40Plan | CVE-2022-29472No exploit | An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.8 | — | 4.5% | Oct 25, 2022 |
40Plan | CVE-2022-33206No exploit | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.9 | — | 4.3% | Oct 25, 2022 |
40Plan | CVE-2022-33207No exploit | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.9 | — | 4.3% | Oct 25, 2022 |
40Plan | CVE-2022-33204No exploit | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.9 | — | 4.3% | Oct 25, 2022 |
40Plan | CVE-2022-33205No exploit | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.9 | — | 4.3% | Oct 25, 2022 |
40Plan | CVE-2022-27804No exploit | An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.8 | — | 3.7% | Oct 25, 2022 |
40Plan | CVE-2022-32773No exploit | An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.8 | — | 3.3% | Oct 25, 2022 |
40Plan | CVE-2022-33189No exploit | An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.8 | — | 3.3% | Oct 25, 2022 |
40Plan | CVE-2022-30541No exploit | An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | Critical9.8 | — | 3.3% | Oct 25, 2022 |
40Plan | CVE-2022-29520No exploit | An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-489 | Critical9.8 | — | 2.9% | Oct 25, 2022 |
40Plan | CVE-2022-32454No exploit | A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-121 | Critical9.8 | — | 1.7% | Oct 25, 2022 |
39Monitor | CVE-2022-27805No exploit | An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-284 | Critical9.8 | — | 1.4% | Oct 25, 2022 |
39Monitor | CVE-2022-35244No exploit | A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc.goabode · iota all-in-one security kit firmware · CWE-134 | Critical9.8 | — | 1.3% | Oct 25, 2022 |
39Monitor | CVE-2022-29477No exploit | An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-798 | Critical9.8 | — | 1.3% | Oct 25, 2022 |
39Monitor | CVE-2022-29889No exploit | A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-798 | Critical9.8 | — | 1.2% | Oct 25, 2022 |
39Monitor | CVE-2022-33938No exploit | A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-134 | Critical9.8 | — | 0.9% | Oct 25, 2022 |
39Monitor | CVE-2022-35875No exploit | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-134 | Critical9.8 | — | 0.9% | Oct 25, 2022 |
39Monitor | CVE-2022-35874No exploit | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-134 | Critical9.8 | — | 0.9% | Oct 25, 2022 |
39Monitor | CVE-2022-35876No exploit | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-134 | Critical9.8 | — | 0.9% | Oct 25, 2022 |
39Monitor | CVE-2022-35877No exploit | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-134 | Critical9.8 | — | 0.9% | Oct 25, 2022 |
37Monitor | CVE-2022-30603No exploit | An OS command injection vulnerability exists in the web interface /action/iperf functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-78 | High8.8 | — | 5.5% | Oct 25, 2022 |
- CVE-2022-3319541Plan
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 10.0No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3319241Plan
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 10.0No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3319341Plan
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 10.0No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3319441Plan
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 10.0No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-2947240Plan
An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 5%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3320640Plan
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.
CriticalCVSS 9.9No exploitEPSS 4%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3320740Plan
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.
CriticalCVSS 9.9No exploitEPSS 4%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3320440Plan
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.
CriticalCVSS 9.9No exploitEPSS 4%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3320540Plan
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.
CriticalCVSS 9.9No exploitEPSS 4%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-2780440Plan
An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 4%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3277340Plan
An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3318940Plan
An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3054140Plan
An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-2952040Plan
An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3245440Plan
A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 2%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-2780539Monitor
An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3524439Monitor
A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-2947739Monitor
An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-2988939Monitor
A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3393839Monitor
A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3587539Monitor
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3587439Monitor
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3587639Monitor
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3587739Monitor
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 1%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2022-3060337Monitor
An OS command injection vulnerability exists in the web interface /action/iperf functionality of Abode Systems, Inc.
HighCVSS 8.8No exploitEPSS 5%goabode · iota all-in-one security kit firmwareOct 25, 2022