The 1.x and 2.x firmware is vulnerable to remote file inclusion (RFI) due to allow_url_fopen being enabled and arguments are not being checked prior to being used in file operations. Since the 3.x firmware uses a redesigned WebUI it is not affected by this vulnerability.