In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.
https://www.us-cert.gov/ics/advisories/icsa-20-056-05
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6982