The company has disclosed another CVSS severity 10 flaw in its internet-facing appliance, just months after a separate pre-authentication flaw in the same product was exploited as a zero-day.