An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.Referenceshttps://github.com/cczzmm/IOT-POC/tree/main/Ikuai