Authorized users may install a maliciously modified package file when updating the device via the web user interface. The user may inadvertently use a package file obtained from an unauthorized source or a file that was compromised between download and deployment.
Credits
Ron Brash of aDolus Technology Inc. reported these vulnerabilities to CISA.