edoardottt discovered this 0day aka CVE-2022-44019.
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
References:
https://www.edoardoottavianelli.it/CV...
https://nvd.nist.gov/vuln/detail/CVE-...