In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.
schneider-electric u.motion builder