The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint (\'ipfilter.cgi\') that allows the user to manage network filtering on the unit. This endpoint is vulnerable to a command injection. An authenticated attacker can leverage this issue to execute arbitrary commands as \'root\'.