A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
https://www.gegridsolutions.com/app/DownloadFile.aspx?prod=RT430&type=21&file=5