hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.706
EPSS Ranking 98.6%