Product
An authenticated remote attacker with administrative privileges can execute arbitrary commands with root permissions via a crafted GET request to the /api/iodd/config endpoint.