setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
https://blog.xlab.qianxin.com/catddos-derivative-en/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-11021