An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7
https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbp