Remote command injection via a crafted HTTP request, caused by insufficient input validation
cmdPacketCapture() function in emfd executable runs system() with insufficient input validation on mac attribute. As a result a crafted POST request with attribute xcmd=spectra-analysis to the web interface page /admin/_cmdstat.jsp injects OS command.