These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01
https://exchange.xforce.ibmcloud.com/vulnerabilities/80202
https://exchange.xforce.ibmcloud.com/vulnerabilities/80200
http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf
http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88