CVE-2011-5010
EXPLOITEDCtekproducts Skyrouter - Access Control
Title source: ruleDescription
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotehardware
https://www.exploit-db.com/exploits/18172
metasploit
WORKING POC
NORMAL
by savant42 · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/ctek_skyrouter.rb
References (5)
Scores
EPSS
0.8341
EPSS Percentile
99.3%
Details
VulnCheck KEV
2020-12-01
CWE
CWE-264
Status
published
Products (2)
ctekproducts/skyrouter
4200
ctekproducts/skyrouter
4300
Published
Dec 25, 2011
Tracked Since
Feb 18, 2026