Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.
https://www.youtube.com/watch?v=l08DHB08Gow
https://packetstormsecurity.com/files/162563/OpenPLC-WebServer-3-Remote-Code-Execution.html