A critical command injection vulnerability has been discovered in ICP DAS UA-2200 and UA-5200 devices up to firmware version 20260704. The flaw exists in the ArmAngstromInstructionSet function within the /CGI?RestApi=SetHostname endpoint, where manipulation of the ParameterArray argument enables command injection. The vulnerability is remotely exploitable without physical access to the affected device. A public exploit has been published, increasing the risk of active exploitation. The vendor was notified early in the disclosure process but did not respond, leaving users without an official patch or mitigation guidance. This affects industrial IoT/OT devices commonly used in automation and control environments. The unpatched status and public exploit availability make this a high-priority concern for organizations using these devices.