In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.