Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.