A critical command injection vulnerability has been identified in ICP DAS UA-2200 and UA-5200 devices up to firmware version 20260704. The flaw resides in the function ArmAngstromInstructionSet within the /CGI?RestApi=SetHostname endpoint. An attacker can manipulate the ParameterArray argument to inject arbitrary commands remotely. The exploit has been publicly disclosed and is available for use. The vendor was contacted prior to disclosure but did not respond. No patch or mitigation from the vendor has been communicated. This vulnerability poses a significant risk to industrial and OT environments where these devices are deployed.