Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.