It’s a community forum. Official IPS support is only guaranteed through support tickets. So all answers here are purely voluntary and a favour of other Invision Community users. We will decide if it’s worth our time to answer and we also might consider HOW the questions is asked. The tone on of certain people here might not be all that motivating to give helpful answers.
But anyway: In the end, all of these functions are possible attack vectors. For potential attackers (just like potential burglars) its usually a case of “once you’re in, you’re in”. There is nothing specific that happens, when you leave your backdoor open and there is nothing specific that happens to have these commands active. But IF they are being used in a malicious way, then the results are potentially very serious. Essentially, your server can be taken over and used for all kinds of bad things. So if your site doesn’t need those functions anyway, it’s best to have them disabled. It’s highly appreciated that IPS has a warning function for that.