CVE-2011-5010: Ctekproducts Skyrouter

High severity, CVSS 10.0. EPSS: 65.7% chance of exploitation in the next 30 days.

apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action.

Affected products

  • Ctekproducts Skyrouter: version 4200 only; version 4300 only

Published 2011-12-25. Last modified 2026-06-16.