OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows malicious users to execute system commands as root via the "secret_key" URL parameter.
asustor data_master 3.1.1