A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-46845
https://cert.vde.com/en/advisories/VDE-2024-032