cgi_refresh_db/FTP_Server_BlockIP_Add/FTP_Server_BlockIP_Del of the file /cgi-bin/app_mgr.cgi. Such manipulation leads to command injection.This vulnerability is documented as CVE-2026-4205. The attack can be executed remotely. Additionally, an exploit exists.