OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows malicious users to execute system commands by modifying the filename POST parameter.
asustor data_master 3.1.1