Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
https://www.securityweek.com/cisa-warns-of-pixel-phone-vulnerability-exploitation/
https://blog.sonicwall.com/en-us/2023/11/sunhillo-sureline-command-injection-vulnerability/