The dhcp.client program shipped with QNX 4.25 is setuid root.
This obviously enables a normal user to control the NIC's configuration and produce some other attacks such as if the system has some services which depend on 'host/ip based' authentication, for example: NFS, NIS, rlogin, etc.