CVE-2011-5010
EXPLOITEDCtek SkyRouter 4200 and 4300 - Remote Code Execution via PINGADDRESS Parameter
Title source: llmExploitation Summary
CVE-2011-5010 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including Metasploit, savant42, including a Metasploit module exploits/unix/http/ctek_skyrouter.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated command injection vulnerability in CTEK SkyRouter 4200 and 4300 devices via the 'cfg_ethping.cgi' endpoint. It sends a crafted POST request with a malicious payload in the 'PINGADDRESS' parameter to achieve remote code execution.
Description
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action.
Exploits (2)
This Metasploit module exploits an unauthenticated command injection vulnerability in CTEK SkyRouter 4200 and 4300 devices via the 'cfg_ethping.cgi' endpoint. It sends a crafted POST request with a malicious payload in the 'PINGADDRESS' parameter to achieve remote code execution.
This Metasploit module exploits an unauthenticated command injection vulnerability in CTEK SkyRouter 4200 and 4300 via the `cfg_ethping.cgi` endpoint. It sends a crafted POST request with a payload appended to the `PINGADDRESS` parameter, achieving remote command execution.