Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Savant42

#23430of 53,632
10Total CVSS
Vulnerabilities · 1
PT-2011-5165
10
2011-12-25
Ctek · Ctek Skyrouter · CVE-2011-5010
**Name of the Vulnerable Software and Affected Versions** Ctek SkyRouter versions 4200 and 4300 **Description** The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the `PINGADDRESS` parameter for a "u" action in the `apps/a3/cfg ethping.cgi` endpoint. **Recommendations** For Ctek SkyRouter versions 4200 and 4300, avoid using the `PINGADDRESS` parameter in the affected endpoint until the issue is resolved. Restrict access to the `cfg ethping.cgi` endpoint to minimize the risk of exploitation.