An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua.
https://github.com/istoreos/istoreos
https://github.com/PRISMI-Team/VulnDisclos/blob/main/Routers/iStoreOS/authorized-rce.md
https://fw.koolcenter.com/iStoreOS/x86_64_efi/
https://doc.linkease.com/zh/guide/istoreos/install_vmware.html