TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.
https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-vufm-1-e