OpenDreambox 2.0.0 is susceptible to remote code execution via the webadmin plugin. Remote attackers can execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI in enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py.
View the template here CVE-2017-14135.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-14135