An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-50463
https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt