Hacker News new | ask | show | jobs
by hello_computer 673 days ago
4th bullet from the bottom sounds credible to me:

> Supports the execution of shell commands on behalf of valid SPA packets.

Even if it were only a statically configured command (no idea if it is or isn't), as soon as that door is opened, it leads to a morass.