OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.21.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.
https://www.universal-robots.com/developer/communication-protocol/dashboard-server/