FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iomode, apmode, ioaction, ioiniface, ioinset, ioinip, ioinmask, ioingw, iooutiface, iooutset, iooutmask, iooutgw, iface, or domain parameter to /www/script/configiface.php, or the newSSID, hostapdsecure, hostapdwpapassphrase, or supplicantssid parameter to /www/page_config.php.