Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
https://github.com/zokirtolqunov4-dev/CVE-2026-XXXX-silverpeak-webgms-9.5.6-exposed-admin
https://www.tp-link.com/us/security
https://seclists.org/fulldisclosure/2020/May/4