NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.Referenceshttps://www.twcert.org.tw/tw/cp-132-10856-4979f-1.htmlhttps://www.twcert.org.tw/en/cp-139-10857-c46f7-2.html