Vendor
SambaBox versions prior to 5.4.1 are vulnerable to OS command injection, allowing unauthenticated attackers to execute arbitrary commands with application privileges.